CVE-2026-76561

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-08 08:17

Updated : 2026-09-08 19:08


NVD link : CVE-2026-76561

Mitre link : CVE-2026-76561

CVE.ORG link : CVE-2026-76561


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')