A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-24 16:16
Updated : 2026-07-25 02:16
NVD link : CVE-2026-17039
Mitre link : CVE-2026-17039
CVE.ORG link : CVE-2026-17039
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
