An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
Remove unnecessary version and topology details from the unauthenticated response.
References
History
Tue, 01 Sep 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 CWE-284 |
Tue, 01 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session. | |
| Title | Pki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security domain hosts | |
| First Time appeared |
Redhat
Redhat certificate System Redhat enterprise Linux |
|
| CPEs | cpe:/a:redhat:certificate_system:9 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat certificate System Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-01T12:37:50.827Z
Reserved: 2026-06-10T12:31:11.556Z
Link: CVE-2026-53682
No data.
Status : Received
Published: 2026-09-01T13:19:47.067
Modified: 2026-09-01T13:19:47.067
Link: CVE-2026-53682
No data.
OpenCVE Enrichment
Updated: 2026-09-01T14:00:04Z