Skip to content
Red HatCVE-2026-18047

Red Hat Dogtag PKI: denial of service

Medium6.5CVE-2026-18047 · Published Jul 28, 2026

A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker can bypass the Tomcat authentication constraint while RESTEasy still routes the request to the handler, allowing unauthorized toggling of the ACME service state including persistent denial of service.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Certificate System 10
Product
all versionsNo fix yet
Red Hat Certificate System 11
Product
all versionsNo fix yet
Red Hat Certificate System 9
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-288

More Red Hat advisories

All Red Hat
Advisory
Red Hat CRIU: code injection
High7.8Jul 28
Red Hat sg3_utils. The sg_inq command: code execution
High7.6Jul 28
A flaw was found in openshift/oauth-proxy
High8.5Jul 28
Red Hat GStreamer: out-of-bounds read
Low3.3Jul 28
Red Hat file-sgi plugin: integer overflow
Medium5.5Jul 27
Red Hat file-fits plugin: integer overflow
High7.8Jul 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.