CVE-2026-104988
Received Received - Intake

CMCAuthForEST Authentication Bypass in Dogtag PKI

Vulnerability report for CVE-2026-104988, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: redhat-SADP

Description

A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem's agent certificate, which causes downstream authorization checks to treat the request as agent-privileged. An authenticated EST user can exploit this to obtain CA-signed certificates with arbitrary subject names.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
redhat dogtag_pki pki-core
redhat pki-core *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Dogtag PKI (pki-core) where the CMCAuthForEST authentication plugin fails to properly handle EST fullcmc enrollment requests when BasicAuth is used without a TLS client certificate. Instead of rejecting the request, it incorrectly retains the EST subsystem's agent certificate, causing downstream checks to treat the request as privileged. This allows an authenticated EST user to bypass authorization and obtain CA-signed certificates with arbitrary subject names.

Detection Guidance

Check Dogtag PKI logs for EST fullcmc enrollment requests using BasicAuth without a client TLS certificate. Look for sessions where SSL_CLIENT_CERT retains the EST subsystem's agent certificate instead of the user's certificate. Verify if CMC signer Subject DN matches the agent certificate during authorization checks.

Impact Analysis

An authenticated EST user could exploit this to impersonate any entity by obtaining CA-signed certificates with arbitrary subject names. This could lead to unauthorized access, data breaches, or fraudulent activities if the certificates are used to authenticate or encrypt communications.

Compliance Impact

This vulnerability could violate compliance with GDPR, HIPAA, and other regulations by enabling unauthorized certificate issuance, which undermines authentication and encryption controls. It risks exposing sensitive data and violating integrity requirements for systems relying on PKI for security.

Mitigation Strategies

Disable Basic authentication for all users by removing the UserPasswords field for user entries in the EST DS server. Ensure EST services enforce mutual TLS (mTLS) client certificates instead of BasicAuth. Update Dogtag PKI to the latest patched version if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104988. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart