CVE-2026-42769
Description
OpenSSL's CMP certificate validation flaw allows RA credentials to escalate trust to the root CA level.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
OpenSSL's CMP certificate validation flaw allows RA credentials to escalate trust to the root CA level.
Vulnerability
An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual. A typo in the certificate chain building code led to adding an incorrect certificate to the chain, meaning only the issuer name and algorithm OIDs were verified. This affects OpenSSL versions prior to the patched releases, excluding FIPS modules. [1]
Exploitation
An attacker with valid Registration Authority (RA) level credentials can generate a new key pair and use a crafted self-signed certificate in its id-it-rootCaKeyUpdate CMP messages. Affected CMP clients would accept this crafted certificate as a new trust anchor, effectively replacing the root CA certificate for CMP clients with an arbitrary root CA certificate. [1]
Impact
The Registration Authority could replace the root CA certificate for the CMP clients with an arbitrary root CA certificate. This allows an attacker to escalate credentials from the Registration Authority (RA) level to the root Certification Authority (root CA) level. [1]
Mitigation
OpenSSL versions prior to the patched releases are vulnerable. Specific patched versions are expected to be released. The FIPS modules are not affected. [1]
AI Insight generated on Jun 9, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
454d0989997e5777b363b16fcd35cd473a271d531f21c0fe9Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/openssl/security/commit/54d0989997e5fc26057009a9782c3441ce3842fbnvd
- github.com/openssl/security/commit/777b363b16fcf2153bb3ded39dc3838713667c44nvd
- github.com/openssl/security/commit/d35cd473a271bf3ce7bf3d32af53217fb83ae92cnvd
- github.com/openssl/security/commit/d531f21c0fe99067a66fc0ff1161ef127f9cd70bnvd
- openssl-library.org/news/secadv/20260609.txtnvd
News mentions
1- OpenSSL Project: 18 Vulnerabilities Disclosed Together on June 9, 2026Vypr Intelligence · Jun 9, 2026