CVE-2026-30836

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:smallstep:step-ca:*:*:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc1:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc2:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc3:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc4:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc5:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc6:*:*:*:go:*:*

History

No history.

Information

Published : 2026-03-19 21:17

Updated : 2026-06-17 10:33


NVD link : CVE-2026-30836

Mitre link : CVE-2026-30836

CVE.ORG link : CVE-2026-30836


JSON object : View

Products Affected

smallstep

  • step-ca
CWE
CWE-287

Improper Authentication

CWE-295

Improper Certificate Validation