Skip to finding
important · Identity — Edge

A low-privilege Dogtag EST account can mint CA-signed certificates for arbitrary identities.

Affects

Dogtag PKI enterprise certificate-authority services on Linux, including affected Red Hat Certificate System and RHEL deployments.

The path applies to an EST fullcmc endpoint using HTTP Basic authentication and requires only valid EST user credentials.

Detail and 1 source

Without an end-user TLS certificate, a stale subsystem-agent certificate causes downstream authorization to treat the request as agent-privileged.

Deployments that enforce mutual TLS are not susceptible to this path.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, October 5, 2026