CVE-2026-53682

An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-01 13:19

Updated : 2026-09-01 21:03


NVD link : CVE-2026-53682

Mitre link : CVE-2026-53682

CVE.ORG link : CVE-2026-53682


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-284

Improper Access Control