A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization.
{
"cna_assigner": "redhat",
"cwe_ids": [
"CWE-863"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/17xxx/CVE-2026-17039.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17039.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"316074399866237766631946114809275705407",
"304032644202217914792418196250178772489",
"271072166620417403703013609171720307658"
],
"threshold": 0.9
},
"id": "CVE-2026-17039-556408fa",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dogtagpki/pki/commit/e2de26769761af04b9c56071bd1a1926903c49b6",
"target": {
"file": "base/server/cms/src/com/netscape/cms/evaluators/UserAccessEvaluator.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "287015264954418535157827618078253975241",
"length": 594
},
"id": "CVE-2026-17039-647ea8d5",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dogtagpki/pki/commit/e2de26769761af04b9c56071bd1a1926903c49b6",
"target": {
"file": "base/server/cms/src/com/netscape/cms/evaluators/UserAccessEvaluator.java",
"function": "evaluate"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "105373230792781450319369605943048469833",
"length": 2598
},
"id": "CVE-2026-17039-afc6f0f2",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dogtagpki/pki/commit/e2de26769761af04b9c56071bd1a1926903c49b6",
"target": {
"file": "base/server/cms/src/com/netscape/cms/servlet/cert/EnrollmentProcessor.java",
"function": "processEnrollment"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"192621335370043488557371494291344240974",
"140225703866687649211862911076029626091",
"33103683099143677841209605281451763592"
],
"threshold": 0.9
},
"id": "CVE-2026-17039-f90e7fee",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dogtagpki/pki/commit/e2de26769761af04b9c56071bd1a1926903c49b6",
"target": {
"file": "base/server/cms/src/com/netscape/cms/servlet/cert/EnrollmentProcessor.java"
}
}
]
"2026-08-12T09:37:50Z"