Impact
The flaw in pki-core causes the CA renewal path to omit the realm‑based authorization check that is present in the enrollment path. An authenticated user who belongs to one realm can therefore submit a renewal request for a certificate that was issued in another realm without that second realm’s authorization. This missing guard constitutes a CWE‑863 style missing check of a required principal to a requested resource and permits issuing a certificate under a realm the requester is not authorized to use.
Affected Systems
Red Hat Certificate System releases 9, 10 and 11, as well as Red Hat Enterprise Linux distributions from version 6 through 10, are affected. The vulnerability is present only when a realm‑based authorization manager is configured for multi‑tenant or delegated sub‑CA setups; deployments that do not use a realm‑mapped authorization manager or rely on the default renewal profiles without an authz.acl are not exposed.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity, and the EPSS score of less than 1 % suggests a low probability of widespread exploitation. The flaw is exploitable by any authenticated CA user capable of issuing renewal requests, without requiring additional privileges or filesystem compromise. The vulnerability is not listed in the CISA KEV catalog, meaning no known active exploitation exists. Until a vendor update is applied, the only feasible mitigation is to enforce a stricter renewal profile that blocks cross‑realm or cross‑user renewals.
OpenCVE Enrichment