Advisory · CVE-2026-104988
Dogtag PKI EST flaw lets an authenticated user mint certificates for arbitrary names
An authenticated EST user can obtain CA-signed certificates with arbitrary subject names because a Dogtag PKI enrollment check treats the request as agent-privileged.
- Vendor
- Red Hat
- Product
- Red Hat Certificate System
- Identifier / CWE
- CVE-2026-104988
CWE-290 - Action timing
- Immediate
Explain it like I’m five
The enrollment desk should check the visitor's own ID badge. Instead it glances at the badge left on the desk by the last staff member and waves the visitor through as staff, then stamps official certificates in whatever name the visitor asks for.
- 01EST request
An authenticated EST user submits a fullcmc enrollment request using Basic authentication and no client certificate.
- 02Stale session identity
The session keeps the EST subsystem agent certificate instead of the requester's identity.
- 03Agent-level authorization
Downstream checks treat the request as agent-privileged and skip normal profile constraints.
- 04Arbitrary certificate issued
The CA signs a certificate with a subject name the requester was never entitled to.
What happened
Red Hat describes a flaw in Dogtag PKI (pki-core) behind Red Hat Certificate System. The CMCAuthForEST authentication plugin fails open when an Enrollment over Secure Transport (EST) fullcmc request arrives with Basic authentication and no end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem agent certificate, so downstream authorization treats the request as agent-privileged. An authenticated EST user can then obtain CA-signed certificates with arbitrary subject names (CVE-2026-104988, CVSS 8.1).
Per Red Hat, the flaw needs EST services configured and reachable with HTTP Basic authentication enabled. Deployments that do not expose EST fullcmc enrollment, or that enforce mutual TLS client certificates, are not susceptible. Red Hat lists Red Hat Certificate System 10 and 11 and Red Hat Enterprise Linux 10 as affected in its CVE data. No fixed build was listed in the Red Hat sources checked for this note, so treat the vendor mitigation below as the immediate control rather than assuming a patch level.
What to do
- Inventory Dogtag PKI and Red Hat Certificate System deployments, including FreeIPA-backed CAs, and find every EST endpoint with fullcmc enrollment enabled.
- Apply Red Hat’s mitigation now: disable Basic authentication for EST, which Red Hat describes as removing the UserPasswords field for user entries in the EST directory server, and prefer mutual TLS client certificates.
- Restrict network access to EST enrollment endpoints to known enrolling systems while the mitigation is rolled out.
- Audit CA issuance records for EST fullcmc enrollments, especially certificates with unexpected subject names, issuances outside normal provisioning windows, or identities that do not match the authenticated account.
- Revoke any certificate that cannot be tied to a legitimate enrollment, and review where those identities are trusted (TLS, smart card or client-auth, and code or device identity stores).
- Track the Red Hat CVE page for fixed packages and apply them when Red Hat publishes them; verify the deployed build afterwards instead of relying on package presence alone.
Management note
A CA that will sign arbitrary names on an authenticated user’s say-so quietly breaks every control that trusts those certificates. The exposure is narrow (EST with Basic auth), but where it exists the right response is mitigation plus an issuance audit, in that order. If the audit is clean, say so with the log window you actually covered.