Unauthenticated Query Vulnerability in Red Hat Security Domain Inventory
CVE-2026-53682

5.3MEDIUM

What is CVE-2026-53682?

A security vulnerability allows unauthenticated users to access sensitive information related to the Security Domain's internal hosts. By querying the endpoint /ca/rest/securityDomain/hosts, an attacker can obtain a detailed inventory of PKI and CA hosts, along with their associated roles within the security topology. This unauthorized access does not require a principal, client certificate, or session, potentially exposing critical infrastructure details and increasing the risk of further attacks.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.