---
id: CVE-2026-1709
title: A flaw was found in Keylime
summary: >-
  A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does
  not enforce client-side Transport Layer Security (TLS) authentication. This
  authentication bypass vulnerability allows unauthenticated clients with
  network ac…
severity: critical
cvss: 9.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H'
cwe:
  - CWE-322
  - CWE-322
vendor: keylime
product: keylime
affected:
  - enterprise_linux = 9.0
  - enterprise_linux = 10.0
  - enterprise_linux_eus = 10.0
  - enterprise_linux_for_arm_64 = 9.0_aarch64
  - enterprise_linux_for_arm_64 = 10.0_aarch64
  - enterprise_linux_for_arm_64_eus = 10.0_aarch64
  - enterprise_linux_for_ibm_z_systems = 9.0_s390x
  - enterprise_linux_for_ibm_z_systems = 10.0_s390x
  - enterprise_linux_for_ibm_z_systems_eus = 10.0_s390x
  - enterprise_linux_for_power_little_endian = 9.0_ppc64le
  - enterprise_linux_for_power_little_endian = 10.0_ppc64le
  - enterprise_linux_for_power_little_endian_eus = 10.0_ppc64le
  - keylime < 7.12.0
patched:
  - keylime 7.12.0
published: '2026-02-06'
updated: '2026-06-27'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-1709'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:2224'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:2225'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:2298'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-1709'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2435514'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:2224'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:2225'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:2298'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-1709'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2435514'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1709.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
epss: 0.05525
epssPercentile: 0.92464
ingestedAt: '2026-06-29T13:24:34.639Z'
---

## Overview

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing agents, retrieving public Trusted Platform Module (TPM) data, and deleting agents, by connecting without presenting a client certificate.

## Affected

- `enterprise_linux = 9.0`
- `enterprise_linux = 10.0`
- `enterprise_linux_eus = 10.0`
- `enterprise_linux_for_arm_64 = 9.0_aarch64`
- `enterprise_linux_for_arm_64 = 10.0_aarch64`
- `enterprise_linux_for_arm_64_eus = 10.0_aarch64`
- `enterprise_linux_for_ibm_z_systems = 9.0_s390x`
- `enterprise_linux_for_ibm_z_systems = 10.0_s390x`
- `enterprise_linux_for_ibm_z_systems_eus = 10.0_s390x`
- `enterprise_linux_for_power_little_endian = 9.0_ppc64le`
- `enterprise_linux_for_power_little_endian = 10.0_ppc64le`
- `enterprise_linux_for_power_little_endian_eus = 10.0_ppc64le`
- `keylime < 7.12.0`

## Remediation

Upgrade past the affected range:

- `keylime 7.12.0`
