Vulnerability in Dogtag PKI's ACME Responder Allows Unauthorized Service State Modification
CVE-2026-18047
6.5MEDIUM
What is CVE-2026-18047?
A vulnerability exists in Dogtag PKI's ACME responder due to improper security constraints in the web.xml configuration. This flaw allows unauthenticated attackers to exploit a URL pattern matching issue, leading to potential unauthorized access. By appending a trailing slash to specific admin-only endpoints, attackers can bypass the authentication mechanism enforced by Apache Tomcat. This can result in unauthorized toggling of the ACME service state, which may lead to persistent service disruptions.