Junglewise Threat Intelligence

CVE-2026-53682: Red Hat Dogtag PKI unauthenticated host enumeration

CVE-2026-53682 · Severity: medium · CVSS 5.3 · Published 2026-09-01

Vendors: Red Hat.

Executive brief

An unauthenticated attacker can query a Red Hat Dogtag PKI/CA REST API endpoint to retrieve detailed information about the internal certificate authority infrastructure, including hostnames and security domain topology. While this does not directly expose credentials or sensitive data, it provides reconnaissance information that enables follow-on targeted attacks against the PKI infrastructure itself.

Technical details

The vulnerability exists in Dogtag PKI's REST API, specifically the GET /ca/rest/securityDomain/hosts endpoint, which returns structured data enumerating internal PKI/CA hosts, roles, and security domain topology without requiring authentication (no principal, client certificate, or session). This is an information disclosure flaw (CWE-497: Exposure of Sensitive System Information) accessible over the network with low complexity. An unauthenticated attacker can invoke this endpoint to map the PKI infrastructure, identifying participating subsystems and their roles. While the disclosed metadata alone does not compromise confidentiality of credentials or sensitive application data, it serves as a reconnaissance enabler for subsequent targeted attacks. Red Hat rates this as Moderate severity due to the lack of direct credential or data exposure, though the topology information increases attack surface visibility.

Affected products

  • Red Hat Dogtag PKI

Timeline

  • 2026-09-01: disclosed

References