Bug 2526744 - CVE-2026-53682 dogtag-pki: Unauthenticated Dogtag CA REST API exposes Security Domain Hosts [fedora-all]
Summary: CVE-2026-53682 dogtag-pki: Unauthenticated Dogtag CA REST API exposes Securit...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: dogtag-pki
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Endi Sukma Dewata
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["09a4ddb0-c427-4c72-a24c-5...
Depends On:
Blocks: CVE-2026-53682
TreeView+ depends on / blocked
 
Reported: 2026-09-01 11:36 UTC by mkaminsk
Modified: 2026-09-01 11:36 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description mkaminsk 2026-09-01 11:36:30 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Description
An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology / participating subsystems / hostnames). This is information disclosure at an authentication boundary: inventory/relationship metadata is exposed without requiring a principal, client cert, or session. 
An unauthenticated adversary with access to the network could enumerate PKI host/subsystem topology, target high-value Dogtag endpoints, or craft follow-on attacks (SSRF/pivots/phishing) using real internal names. 
Recommendations
There is no reason to share the foreman version in the response and should be masked.


Note You need to log in before you can comment on or make changes to this bug.