Description
An issue was discovered in Keyfactor SignServer before 7.6.0. The output file to which SignerStatusReportWorker logs the report can be set to any path, even one that points to a file that already exists. This gives a user (with admin access) the possibility to write files in arbitrary directories in the server filesystem and potentially overwrite files accessible by the local user JBoss.
Published: 2026-09-15
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Write
Action: Assess Impact
AI Analysis

Impact

The vulnerability allows an administrator to set the log file path for SignerStatusReportWorker to any existing file on the server. By pointing the path to a sensitive file, the attacker can overwrite it, potentially disrupting application behavior or enabling further escalation. The file‑write occurs with the same privileges as the local JBoss user, allowing modification of configuration or executable files, representing a path validation flaw (CWE-706).

Affected Systems

Keyfactor SignServer versions prior to 7.6.0 are affected. The issue manifests when the SignerStatusReportWorker component is used to generate a status report and the log file path is not validated for correct location or existence.

Risk and Exploitability

The exploitation requires administrator access to the SignServer configuration. The CVSS score of 2.7 indicates a low severity, and the EPSS score is < 1% with the vulnerability not listed in CISA’s KEV catalog, indicating a very low exploitation probability in the current public landscape. Nonetheless, an attacker who can overwrite arbitrary files could disrupt service availability, tamper withold for further attacks that target files accessible by the JBoss user.

Generated by OpenCVE AI on September 22, 2026 at 21:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply an update to Keyfactor SignServer 7.6.0 or later, which addresses the log path validation bug.
  • If an update is not immediately possible, restrict administrator privileges to prevent modification of the log file path or move the log directory to a location with strict file permissions so only the system process can write to it.
  • Verify that the log file path does not resolve to a file within directories that contain application configuration or executable files accessible to the JBoss user.

Generated by OpenCVE AI on September 22, 2026 at 21:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Keyfactor SignServer Arbitrary File Write via Log Path Setting

Tue, 22 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Arbitrary File Write via Unvalidated Log Path in Keyfactor SignServer
Weaknesses CWE-22

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-706
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Sun, 20 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title Arbitrary File Write via Unvalidated Log Path in Keyfactor SignServer
Weaknesses CWE-22

Thu, 17 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Keyfactor SignServer Arbitrary File Write via Log Path
Weaknesses CWE-22

Wed, 16 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title Keyfactor SignServer Arbitrary File Write via Log Path
Weaknesses CWE-22

Tue, 15 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Keyfactor
Keyfactor signserver
Vendors & Products Keyfactor
Keyfactor signserver

Tue, 15 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Keyfactor SignServer before 7.6.0. The output file to which SignerStatusReportWorker logs the report can be set to any path, even one that points to a file that already exists. This gives a user (with admin access) the possibility to write files in arbitrary directories in the server filesystem and potentially overwrite files accessible by the local user JBoss.
References

Subscriptions

Keyfactor Signserver
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-22T15:24:27.963Z

Reserved: 2026-02-06T00:00:00.000Z

Link: CVE-2026-25825

cve-icon Vulnrichment

Updated: 2026-09-22T15:23:59.770Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T15:17:14.347

Modified: 2026-09-22T19:56:19.073

Link: CVE-2026-25825

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:45:06Z

Weaknesses
  • CWE-706

    Use of Incorrectly-Resolved Name or Reference