Authentication Bypass in Dogtag PKI Affects Multiple Enrollment Processes
CVE-2026-104988

8.1HIGH

What is CVE-2026-104988?

A significant flaw exists in the Dogtag PKI system's CMCAuthForEST authentication plugin. When an EST fullcmc enrollment request is made through BasicAuth without presenting a valid end-user TLS client certificate, the SSL_CLIENT_CERT session attribute incorrectly retains the agent certificate of the EST subsystem. This vulnerability may lead to downstream authorization checks being misled into granting agent-privileged access. As a result, an authenticated EST user could potentially misuse this defect to generate CA-signed certificates with arbitrary subject names, posing serious security risks to the integrity of certificate issuance processes.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.