A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem's agent certificate, which causes downstream authorization checks to treat the request as agent-privileged. An authenticated EST user can exploit this to obtain CA-signed certificates with arbitrary subject names.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Disable basic authentication for all users. This can be done by removing the field "UserPasswords" for the user entries in the EST DS server.

History

Fri, 02 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem's agent certificate, which causes downstream authorization checks to treat the request as agent-privileged. An authenticated EST user can exploit this to obtain CA-signed certificates with arbitrary subject names.
Title Pki-core: dogtag-pki: redhat-pki: pki: est fullcmc authentication bypass allows certificate mis-issuance with arbitrary subject
First Time appeared Redhat
Redhat certificate System
Redhat enterprise Linux
Weaknesses CWE-290
CPEs cpe:/a:redhat:certificate_system:10
cpe:/a:redhat:certificate_system:11
cpe:/a:redhat:certificate_system:9
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat certificate System
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-02T19:34:33.328Z

Reserved: 2026-10-02T18:56:53.056Z

Link: CVE-2026-104988

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T20:17:01.370

Modified: 2026-10-02T20:17:01.370

Link: CVE-2026-104988

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T20:30:16Z

Weaknesses