A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 08 Sep 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account. | |
| Title | Pki-core: dogtag/pki: certprofile-import allows code execution via unsanitized profile content (externalprocessconstraint) | |
| First Time appeared |
Redhat
Redhat certificate System Redhat enterprise Linux |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:/a:redhat:certificate_system:9 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat certificate System Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2026-09-08T07:55:29.916Z
Updated: 2026-09-08T16:54:19.152Z
Reserved: 2026-08-19T13:01:16.163Z
Link: CVE-2026-76561
No data.
Status : Awaiting Analysis
Published: 2026-09-08T08:17:12.020
Modified: 2026-09-08T19:08:15.590
Link: CVE-2026-76561