Low severity3.1NVD Advisory· Published Jul 24, 2026· Updated Jul 25, 2026
CVE-2026-17039
CVE-2026-17039
Description
A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization.
Affected products
2- Package: https://pypi.org/project/pki-core
Patches
Vulnerability mechanics
References
8- access.redhat.com/security/cve/CVE-2021-20179nvd
- access.redhat.com/security/cve/CVE-2026-17039nvd
- bugzilla.redhat.com/show_bug.cginvd
- github.com/dogtagpki/pki/blob/master/base/ca/database/ds/acl.ldifnvd
- github.com/dogtagpki/pki/blob/master/base/ca/src/main/java/com/netscape/cms/servlet/cert/EnrollmentProcessor.javanvd
- github.com/dogtagpki/pki/blob/master/base/ca/src/main/java/com/netscape/cms/servlet/cert/RenewalProcessor.javanvd
- github.com/dogtagpki/pki/blob/master/base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/CertServlet.javanvd
- github.com/dogtagpki/pki/commit/e2de26769761af04b9c56071bd1a1926903c49b6nvd
News mentions
0No linked articles in our index yet.