Bug 2523749 (CVE-2026-80110) - CVE-2026-80110 pki-core: Dogtag PKI v2 REST ACL filter's reverse-lexicographic tie-break lets a CA Agent invoke the admin-only raw profile creation endpoint
Summary: CVE-2026-80110 pki-core: Dogtag PKI v2 REST ACL filter's reverse-lexicographi...
Keywords:
Status: NEW
Alias: CVE-2026-80110
Deadline: 2026-09-15
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-25 19:53 UTC by OSIDB Bzimport
Modified: 2026-09-21 13:41 UTC (History)
13 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-25 19:53:53 UTC
A flaw was found in pki-core. The v2 REST ACL filter (org.dogtagpki.server.rest.v2.filters.ACLFilter) resolves a request to an ACL permission by regex-matching candidate keys and then selecting the lexicographically largest match via Comparator.reverseOrder().findFirst(), rather than the most specific match. Because the wildcard placeholder character '{' (0x7B) sorts above lowercase ASCII letters, a wildcard key beats a colliding literal key. In the CA's ProfileACL filter, the literal key "POST:raw" (intended to require the profiles.create permission, gated to the Administrators group via the certServer.profile.configuration ACI) collides with the wildcard key "POST:{}" (mapped to profiles.approve, gated to the Certificate Manager Agents group via the certServer.ca.profile ACI). For a request to POST /v2/profiles/raw, both keys match and the wildcard wins, so the endpoint is authorized under profiles.approve instead of profiles.create. Routing to the handler itself is correct (PKIServlet's dispatcher and the sibling AuthMethodFilter both use Comparator.naturalOrder() for the identical collision shape and pick the literal match) -- only ACLFilter's independent authorization tie-break disagrees with its own sibling filters and picks the wrong permission. As a result, an authenticated user holding only the Certificate Manager Agents role -- not an Administrator -- can invoke createProfileRaw, which builds a new certificate profile directly from an attacker-supplied raw byte stream, and can then enable that profile using their own legitimate profiles.approve permission. This lets a CA Agent author and activate an arbitrary certificate-issuance profile, a privilege-escalation path from the CA Agent role to effective control over the CA's issuance policy. The vulnerable code was confirmed present, by direct source and bytecode inspection, in the pki-core 11.6.0 and 11.7.1 lines (RHEL 9); it is absent from the older pki-core 10.x line (RHEL 7/8), which uses a different, unaffected REST architecture. No non-default configuration is required to reach this path on affected versions; the v2 REST API is network-reachable and cert-auth-wired identically to v1 in production IdM/RHCS deployments (confirmed via the ipa-pki-proxy.conf reverse-proxy configuration).


Note You need to log in before you can comment on or make changes to this bug.