Red HatCVE-2026-104988
Red Hat Certificate System 10: authentication bypass by spoofing
No fix yet
A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem's agent certificate, which causes downstream authorization checks to treat the request as agent-privileged. An authenticated EST user can exploit this to obtain CA-signed certificates with arbitrary subject names.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Certificate System 10 Product | all versions | No fix yet |
| Red Hat Certificate System 11 Product | all versions | No fix yet |
| Red Hat Certificate System 9 Product | all versions | No fix yet |
| all versions | No fix yet | |
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 6 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 7 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-290
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 2 | Red Hat, Inc.: CVE records (CNA): code execution | High8.7 | Red Hat+2 more |
| Oct 2 | Red Hat FreeType: resource exhaustion | Medium5.5 | No fix yet |
| Oct 2 | A flaw was found in 389-ds-base | Critical9.0 | No fix yet |
| Oct 1 | Red Hat 389-ds-base: resource exhaustion | High7.5 | No fix yet |
| Oct 1 | Red Hat Satellite 6: SQL injection | Medium6.5 | No fix yet |
| Oct 1 | Red Hat Satellite 6: observable discrepancy | Medium4.3 | No fix yet |