Bug 2487511 (CVE-2026-53682) - CVE-2026-53682 pki-core: dogtag-pki: Unauthenticated Dogtag CA REST API exposes Security Domain Hosts
Summary: CVE-2026-53682 pki-core: dogtag-pki: Unauthenticated Dogtag CA REST API expos...
Keywords:
Status: NEW
Alias: CVE-2026-53682
Deadline: 2026-09-10
Product: Security Response
Classification: Other
Component: vulnerability-draft
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2526744
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-10 12:43 UTC by OSIDB Bzimport
Modified: 2026-09-01 11:36 UTC (History)
16 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-06-10 12:43:45 UTC
Description
An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology / participating subsystems / hostnames). This is information disclosure at an authentication boundary: inventory/relationship metadata is exposed without requiring a principal, client cert, or session. 
An unauthenticated adversary with access to the network could enumerate PKI host/subsystem topology, target high-value Dogtag endpoints, or craft follow-on attacks (SSRF/pivots/phishing) using real internal names. 
Recommendations
There is no reason to share the foreman version in the response and should be masked.


Note You need to log in before you can comment on or make changes to this bug.