SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-17039

LOW · CVSS 3.1 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

A vulnerability exists in the certificate authority renewal process of pki-core, where the realm-based authorization check is bypassed, allowing an authenticated user to renew certificates from a different realm without proper authorization. This could lead to unauthorized certificate issuance, potentially compromising the integrity of the affected realms. Organizations utilizing pki-core for certificate management should prioritize addressing this issue to mitigate risks associated with unauthorized certificate renewals.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-17039
Severity
LOW
CVSS
3.1
EPSS
0.21%

Original NVD Description

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization.