AI and data stack advisories

Severe, 6 weeks2973Projects319

2973 severe, 6 weeks · 319 projects

Red HatCVE-2026-104988

Red Hat Certificate System 10: authentication bypass by spoofing

Red Hat

CVE-2026-104988 · Published Oct 2, 2026 · updated Oct 6, 2026

High8.1
No fix yet
Red Hat advisory

A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem's agent certificate, which causes downstream authorization checks to treat the request as agent-privileged. An authenticated EST user can exploit this to obtain CA-signed certificates with arbitrary subject names.

Affected versions

PackageAffectedFixed in
Red Hat Certificate System 10
Product
all versionsNo fix yet
Red Hat Certificate System 11
Product
all versionsNo fix yet
Red Hat Certificate System 9
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat, Inc.: CVE records (CNA): code execution
High8.7Oct 2
Red Hat FreeType: resource exhaustion
Medium5.5Oct 2
A flaw was found in 389-ds-base
Critical9.0Oct 2
Red Hat 389-ds-base: resource exhaustion
High7.5Oct 1
Red Hat Satellite 6: SQL injection
Medium6.5Oct 1
Red Hat Satellite 6: observable discrepancy
Medium4.3Oct 1