ZeroHour

CVE-2026-76561

moderate

Authenticated Command Injection in Dogtag PKI Profile Import (FreeIPA CA)

CVSS 3.1
7.2 high
EPSS
<1%p46
Published
()
Modified
AI analysis

CVE-2026-76561 is an OS command injection flaw (CWE-78) in Dogtag PKI's certificate profile import functionality, which only validates the profile ID and not the rest of the uploaded profile content. An authenticated user holding CA Administrator privileges can import a crafted certificate profile that abuses Dogtag's ExternalProcessConstraint mechanism, injecting attacker-controlled environment variables into an external process invocation. This yields arbitrary command execution on the certificate authority host in the context of the pkiuser account, with high impact on confidentiality, integrity, and availability. Organizations running Dogtag PKI are affected, most notably where it serves as the certificate authority inside FreeIPA (including Red Hat's Identity Management offering). No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at just 0.6%, reflecting both the lack of public exploit code and the requirement for highly privileged CA Administrator access.

What to do: Patch Dogtag PKI and FreeIPA/Red Hat Identity Management using the fix provided via Red Hat's advisory for CVE-2026-76561, prioritizing hosts where the CA profile import functionality is reachable. Until patched, limit and audit CA Administrator accounts, and review recently imported or modified certificate profiles for unusual ExternalProcessConstraint settings. Because exploitation requires high privileges and no public PoC exists, this is a proactive-patching issue rather than an emergency, but monitor the pkiuser account's process activity for unexpected child processes on CA hosts.

Affected
Dogtag Project (CNA: Red Hat) Dogtag PKI
FreeIPA Project / Red Hat FreeIPA (Certificate Authority component using Dogtag PKI)
Estimated exposure
moderate≈ tens of thousands of FreeIPA/IdM and Dogtag CA servers (deployment-pattern estimate; typically internal, not internet-exposed) — Dogtag PKI ships as the CA engine for FreeIPA, which is the bundled identity-management solution for RHEL/Fedora enterprise environments where deployments are commonly one-to-few CA servers per organization and kept on internal networks,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.