Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
There is no way to mitigate this issue other than applying an update once available. As a partial mitigation, limiting membership in the Certificate Manager Agents group to trusted users reduces exposure, since exploitation requires an authenticated credential in that role.
Mon, 21 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to override a more specific literal-mapped permission when both match. In the CA's profile-management REST API this allows a request to POST /v2/profiles/raw -- intended to require Administrator-level profiles.create permission -- to instead be authorized under the lower-privileged profiles.approve permission held by the default Certificate Manager Agents group. The highest threat from this vulnerability is to confidentiality and integrity of the certificate authority's issuance policy. | |
| Title | Pki-core: dogtag pki v2 rest acl filter's reverse-lexicographic tie-break lets a ca agent invoke the admin-only raw profile creation endpoint | |
| First Time appeared |
Redhat
Redhat certificate System Redhat enterprise Linux |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:/a:redhat:certificate_system:9 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat certificate System Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-21T14:59:06.897Z
Reserved: 2026-08-25T19:49:07.193Z
Link: CVE-2026-80110
Updated: 2026-09-21T14:59:02.611Z
Status : Received
Published: 2026-09-21T15:17:32.060
Modified: 2026-09-21T15:17:32.060
Link: CVE-2026-80110
No data.
OpenCVE Enrichment
Updated: 2026-09-21T15:45:16Z