SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-53682

MEDIUM · CVSS 5.3 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An unauthenticated client can exploit this vulnerability to query the Security Domain hosts inventory, allowing them to obtain detailed information about internal PKI/CA hosts and their roles without any authentication. This exposure could lead to further attacks on the security infrastructure by revealing critical topology and subsystem details. Organizations utilizing affected products should prioritize remediation to protect their internal security architecture from potential reconnaissance and exploitation.

CVE
CVE-2026-53682
Severity
MEDIUM
CVSS
5.3
EPSS
0.13%

Original NVD Description

An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.