Description
A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem's agent certificate, which causes downstream authorization checks to treat the request as agent-privileged. An authenticated EST user can exploit this to obtain CA-signed certificates with arbitrary subject names.
Published: 2026-10-02
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: Authentication bypass leading to unauthorized certificate issuance
Action: Patch ASAP
AI Analysis

Impact

The CMCAuthForEST plugin in Dogtag PKI does not properly verify the presence of a client TLS certificate during an EST "fullcmc" enrollment when Basic Authentication is used. Instead, the SSL_CLIENT_CERT session attribute continues to hold the EST subsystem agent certificate, and downstream authorization checks treat the request as agent‑privileged. An attacker who is authenticated to the EST service can therefore submit enrollment requests that are signed with any chosen subject name, enabling the issuance of CA‑signed certificates that do not reflect the user's identity. This flaw is a classic Authentication Bypass (CWE‑290) that can lead to credential forging, domain impersonation, and the creation of rogue certificates which can be exploited for man‑in‑the‑middle attacks or other fraudulent activities.

Affected Systems

Red Hat Certificate System versions 9, 10, and 11 are affected, as are Red Hat Enterprise Linux releases 6, 7, 8, 9, and 10. The vulnerability resides in the Dogtag PKI (pki-core) component that is bundled with these products.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity flaw. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The bypass requires the attacker to possess valid EST credentials, meaning exploitation is likely limited to insiders or compromised accounts rather than external attackers. Nevertheless, the potential to issue arbitrary certificates represents a significant compromise of the PKI’s integrity, making this vulnerability a high‑value target for privileged users or malicious insiders.

Generated by OpenCVE AI on October 2, 2026 at 20:21 UTC.

Remediation

Vendor Workaround

Disable basic authentication for all users. This can be done by removing the field "UserPasswords" for the user entries in the EST DS server.


OpenCVE Recommended Actions

  • Disable Basic Authentication for all EST users by removing the "UserPasswords" field from the EST directory service entries.
  • Reconfigure the EST subsystem so that enrollment requests over Basic Authentication require a valid TLS client certificate, ensuring that the SSL_CLIENT_CERT attribute is properly set.
  • Apply any vendor‑issued patches or updates to Dogtag PKI as soon as they become available; if no patch exists, monitor Red Hat’s security advisories for an upcoming fix and plan to upgrade the affected PKI component.

Generated by OpenCVE AI on October 2, 2026 at 20:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem's agent certificate, which causes downstream authorization checks to treat the request as agent-privileged. An authenticated EST user can exploit this to obtain CA-signed certificates with arbitrary subject names.
Title Pki-core: dogtag-pki: redhat-pki: pki: est fullcmc authentication bypass allows certificate mis-issuance with arbitrary subject
First Time appeared Redhat
Redhat certificate System
Redhat enterprise Linux
Weaknesses CWE-290
CPEs cpe:/a:redhat:certificate_system:10
cpe:/a:redhat:certificate_system:11
cpe:/a:redhat:certificate_system:9
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat certificate System
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Redhat Certificate System Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-02T19:34:33.328Z

Reserved: 2026-10-02T18:56:53.056Z

Link: CVE-2026-104988

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T20:17:01.370

Modified: 2026-10-02T20:17:01.370

Link: CVE-2026-104988

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T20:30:16Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing