Vulnerability in Dogtag PKI's ACME Responder Allows Unauthorized Service State Modification
CVE-2026-18047

6.5MEDIUM

What is CVE-2026-18047?

A vulnerability exists in Dogtag PKI's ACME responder due to improper security constraints in the web.xml configuration. This flaw allows unauthenticated attackers to exploit a URL pattern matching issue, leading to potential unauthorized access. By appending a trailing slash to specific admin-only endpoints, attackers can bypass the authentication mechanism enforced by Apache Tomcat. This can result in unauthorized toggling of the ACME service state, which may lead to persistent service disruptions.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.