An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.
History

Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.
Title Pki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security domain hosts
First Time appeared Redhat
Redhat certificate System
Redhat enterprise Linux
CPEs cpe:/a:redhat:certificate_system:9
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat certificate System
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2026-09-01T12:37:50.827Z

Updated: 2026-09-01T15:27:06.127Z

Reserved: 2026-06-10T12:31:11.556Z

Link: CVE-2026-53682

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T13:19:47.067

Modified: 2026-09-01T16:17:05.290

Link: CVE-2026-53682

cve-icon Redhat

No data.