{"id":"CVE-2026-104988","title":"A flaw was found in Dogtag PKI (pki-core)","summary":"A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attri…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-290"],"vendor":"Red Hat","product":"redhat-pki:10/redhat-pki","affected":["redhat-pki:10/redhat-pki (all versions)","redhat-pki (all versions)","pki-core","redhat-pki","dogtag-pki (all versions)","pki-core","pki-core","pki-core:10.6/pki-core","pki-core"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T20:17:01.370","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104988","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-104988","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2545316","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-02T22:33:09.844Z","slug":"CVE-2026-104988","body":"## Overview\n\nA flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem's agent certificate, which causes downstream authorization checks to treat the request as agent-privileged. An authenticated EST user can exploit this to obtain CA-signed certificates with arbitrary subject names.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}