Impact
The CMCAuthForEST plugin in Dogtag PKI does not properly verify the presence of a client TLS certificate during an EST "fullcmc" enrollment when Basic Authentication is used. Instead, the SSL_CLIENT_CERT session attribute continues to hold the EST subsystem agent certificate, and downstream authorization checks treat the request as agent‑privileged. An attacker who is authenticated to the EST service can therefore submit enrollment requests that are signed with any chosen subject name, enabling the issuance of CA‑signed certificates that do not reflect the user's identity. This flaw is a classic Authentication Bypass (CWE‑290) that can lead to credential forging, domain impersonation, and the creation of rogue certificates which can be exploited for man‑in‑the‑middle attacks or other fraudulent activities.
Affected Systems
Red Hat Certificate System versions 9, 10, and 11 are affected, as are Red Hat Enterprise Linux releases 6, 7, 8, 9, and 10. The vulnerability resides in the Dogtag PKI (pki-core) component that is bundled with these products.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity flaw. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The bypass requires the attacker to possess valid EST credentials, meaning exploitation is likely limited to insiders or compromised accounts rather than external attackers. Nevertheless, the potential to issue arbitrary certificates represents a significant compromise of the PKI’s integrity, making this vulnerability a high‑value target for privileged users or malicious insiders.
OpenCVE Enrichment