CVE-2026-76561
moderateAuthenticated Command Injection in Dogtag PKI Profile Import (FreeIPA CA)
CVE-2026-76561 is an OS command injection flaw (CWE-78) in Dogtag PKI's certificate profile import functionality, which only validates the profile ID and not the rest of the uploaded profile content. An authenticated user holding CA Administrator privileges can import a crafted certificate profile that abuses Dogtag's ExternalProcessConstraint mechanism, injecting attacker-controlled environment variables into an external process invocation. This yields arbitrary command execution on the certificate authority host in the context of the pkiuser account, with high impact on confidentiality, integrity, and availability. Organizations running Dogtag PKI are affected, most notably where it serves as the certificate authority inside FreeIPA (including Red Hat's Identity Management offering). No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at just 0.6%, reflecting both the lack of public exploit code and the requirement for highly privileged CA Administrator access.
What to do: Patch Dogtag PKI and FreeIPA/Red Hat Identity Management using the fix provided via Red Hat's advisory for CVE-2026-76561, prioritizing hosts where the CA profile import functionality is reachable. Until patched, limit and audit CA Administrator accounts, and review recently imported or modified certificate profiles for unusual ExternalProcessConstraint settings. Because exploitation requires high privileges and no public PoC exists, this is a proactive-patching issue rather than an emergency, but monitor the pkiuser account's process activity for unexpected child processes on CA hosts.
| Dogtag Project (CNA: Red Hat) Dogtag PKI | — |
| FreeIPA Project / Red Hat FreeIPA (Certificate Authority component using Dogtag PKI) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.