CVE-2026-104988High· 8.1▾ TwilightA flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attri…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem's agent certificate, which causes downstream authorization checks to treat the request as agent-privileged. An authenticated EST user can exploit this to obtain CA-signed certificates with arbitrary subject names.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-94416Medium· 6.8An authorization bypass was found in the Ansible Automation Platform (AAP) gateway
CVE-2025-54576High· 7.4github.com/oauth2-proxy/oauth2-proxy: OAuth2-Proxy authentication bypass (CVE-2025-54576)
CVE-2026-95512Medium· 5.5A flaw was found in FreeType, specifically within its CID font loader
CVE-2026-86345Critical· 9.0A flaw was found in 389-ds-base
CVE-2026-86344High· 7.5A flaw was found in 389-ds-base
CVE-2026-103484High· 8.8IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.