---
id: CVE-2026-76561
title: >-
  A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority
  component
summary: >-
  A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority
  component. The certificate profile import functionality does not fully
  validate uploaded profile content beyond the profile ID. An authenticated user
  with CA Admi…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: Red Hat
product: pki-core
affected:
  - pki-core (all versions)
  - dogtag-pki (all versions)
  - pki-core
  - pki-core (all versions)
  - pki-core (all versions)
  - 'pki-core:10.6/pki-core (all versions)'
  - pki-core (all versions)
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:08:15.590'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76561'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-76561'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2519523'
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-08T16:40:56.175463Z'
epss: 0.0058
epssPercentile: 0.45353
ingestedAt: '2026-09-08T15:33:26.982Z'
---

## Overview

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
