Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Remove unnecessary version and topology details from the unauthenticated response.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 01 Sep 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 CWE-284 |
Tue, 01 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session. | |
| Title | Pki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security domain hosts | |
| First Time appeared |
Redhat
Redhat certificate System Redhat enterprise Linux |
|
| CPEs | cpe:/a:redhat:certificate_system:9 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat certificate System Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-01T15:27:06.127Z
Reserved: 2026-06-10T12:31:11.556Z
Link: CVE-2026-53682
No data.
Status : Received
Published: 2026-09-01T13:19:47.067
Modified: 2026-09-01T16:17:05.290
Link: CVE-2026-53682
No data.
OpenCVE Enrichment
Updated: 2026-09-01T14:00:04Z