{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/dogtag-pki/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:dogtag_pki:pki_core:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-104988"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["pki-core"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","pki","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["Dogtag PKI"],"content_html":"\u003cp\u003eA security vulnerability (CVE-2026-104988) exists within the CMCAuthForEST authentication plugin of Dogtag PKI (pki-core). The issue arises when an Enrollment over Secure Transport (EST) fullcmc enrollment request is submitted using Basic Authentication in the absence of an end-user TLS client certificate. In this scenario, the application fails to correctly clear the session state. Specifically, the 'SSL_CLIENT_CERT' session attribute persists and retains the EST subsystem's agent certificate. Because downstream authorization mechanisms rely on this attribute to verify the requester's identity, the system incorrectly evaluates the request as having been made by an agent with elevated privileges. An authenticated user can leverage this logic flaw to successfully request and obtain CA-signed certificates containing arbitrary subject names, effectively bypassing standard enrollment restrictions. This vulnerability poses a significant risk to the integrity of the PKI environment, as unauthorized entities could issue valid certificates.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows an authenticated user to perform unauthorized certificate issuance. If exploited, an attacker could obtain valid CA-signed certificates with arbitrary subject names, facilitating impersonation, unauthorized authentication to internal services, and potential bypass of security controls that rely on certificate-based identity. The impact is assessed as high given the ability to manipulate the primary trust mechanism of the organization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor for unauthorized certificate requests targeting the EST interface, specifically those lacking a client TLS certificate but succeeding via Basic Auth.\u003c/li\u003e\n\u003cli\u003eAudit CA logs for certificates issued with unexpected or non-standard subject names.\u003c/li\u003e\n\u003cli\u003eApply the security patch for Dogtag PKI (pki-core) provided by the vendor to ensure proper clearing of the SSL_CLIENT_CERT session attribute when authentication methods are mismatched.\u003c/li\u003e\n\u003cli\u003eReview all service accounts associated with EST subsystems to ensure that only authorized administrative entities have access to fullcmc enrollment endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T22:27:21Z","date_published":"2026-10-02T22:27:21Z","id":"https://feed.craftedsignal.io/briefs/2026-10-dogtag-pki-auth-bypass/","summary":"An authentication bypass vulnerability in the Dogtag PKI CMCAuthForEST plugin allows authenticated users to obtain CA-signed certificates with arbitrary subject names due to improper session attribute handling during EST fullcmc requests.","title":"Authentication Bypass in Dogtag PKI CMCAuthForEST Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-dogtag-pki-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Dogtag PKI","version":"https://jsonfeed.org/version/1.1"}