Back to overview

CVE-2026-18047

MEDIUM
6.5
CVSS 3.1
Description
A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker can bypass the Tomcat authentication constraint while RESTEasy still routes the request to the handler, allowing unauthorized toggling of the ACME service state including persistent denial of service.

Metadata

CVE ID
CVE-2026-18047
State
PUBLISHED
Assigner
redhat
Reserved
2026-07-28 10:15 UTC
Published
2026-07-28 12:44 UTC
Last updated
2026-07-28 13:26 UTC
Primary CWE
CWE-288
Authentication Bypass Using an Alternate Path or Channel
Vendor / Product
Red Hat / Red Hat Certificate System 10
Sources
cve.org  ·  NVD

Severity & Metrics

6.5 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (9)
VendorProductPlatformVersions
Red Hat Red Hat Certificate System 10
Red Hat Red Hat Certificate System 11
Red Hat Red Hat Certificate System 9
Red Hat Red Hat Certificate System 9
Red Hat Red Hat Enterprise Linux 10
Red Hat Red Hat Enterprise Linux 6
Red Hat Red Hat Enterprise Linux 7
Red Hat Red Hat Enterprise Linux 8
Red Hat Red Hat Enterprise Linux 9
Weakness (CWE)
CWESourceDescription
CWE-288 cna Authentication Bypass Using an Alternate Path or Channel
CVSS scores (1)
ScoreSeverityVersionSourceVector
6.5 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Back to overview