Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Until a fixed package is available, restrict membership in CA Administrator and equivalent roles to fully trusted operators, and audit certificate profile import operations for unexpected or unrecognized profile content. Review any custom ExternalProcessConstraint executable configuration in Dogtag for unnecessary exposure.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account. | |
| Title | Pki-core: dogtag/pki: certprofile-import allows code execution via unsanitized profile content (externalprocessconstraint) | |
| First Time appeared |
Redhat
Redhat certificate System Redhat enterprise Linux |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:/a:redhat:certificate_system:9 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat certificate System Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-08T16:54:19.152Z
Reserved: 2026-08-19T13:01:16.163Z
Link: CVE-2026-76561
No data.
Status : Received
Published: 2026-09-08T08:17:12.020
Modified: 2026-09-08T09:18:21.107
Link: CVE-2026-76561
No data.
OpenCVE Enrichment
Updated: 2026-09-08T09:30:07Z