Junglewise Threat Intelligence

CVE-2026-14440: Cloudflare Universal SSL CAA enforcement bypass

CVE-2026-14440 · Severity: info · CVSS 7.6 · Published 2026-07-01

Vendors: Cloudflare.

Executive brief

Cloudflare's Universal SSL feature, which automatically manages security certificates for websites, contains a configuration flaw that can bypass certain advanced security restrictions set by customers. Specifically, if a customer tries to limit certificate issuance to a specific account or validation method, Cloudflare's automated system may override these settings with more permissive ones. This could theoretically allow a sophisticated attacker to obtain a fraudulent security certificate for a customer's domain, potentially allowing them to intercept or spoof encrypted web traffic.

Technical details

Cloudflare's Universal SSL feature automatically manages Certificate Authority Authorization (CAA) Resource Record Sets (RRsets) for customer zones. This auto-managed RRset is designed to be permissive and takes precedence over customer-configured CAA records at query time. Consequently, when a customer attempts to implement stricter controls using RFC 8657 parameters (such as 'accounturi' or 'validationmethods'), these constraints are not observed by the Certificate Authority because the Cloudflare-served RRset lacks them. An attacker who controls an ACME account at a permitted CA and can satisfy domain control validation requirements could potentially obtain a browser-trusted certificate for the target domain. Mitigation requires disabling Universal SSL for zones where strict RFC 8657 enforcement is necessary.

Affected products

  • Cloudflare Universal SSL All versions prior to July 2026

Timeline

  • 2026-07-01: disclosed: Vulnerability disclosed by Cloudflare and assigned CVE-2026-14440.

References