CVE-2026-76561High· 7.2▾ TwilightA flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Admi…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.6%
A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80110High· 8.1A flaw was found in pki-core
CVE-2026-85013High· 7.3A flaw was found in environment-modules
CVE-2026-10805Medium· 6.7A flaw was found in NetworkManager
CVE-2025-69262High· 7.5pnpm is a package manager
CVE-2026-95508High· 7.4Libslirp: libslirp: heap buffer overflow in dhcpv6/tftp response builders on small interface mtu
CVE-2026-95511High· 8.2Cups: cups-filters: cups-filters: lpadmin can escalate to root via privileged serial backend (cups2root)