Junglewise Threat Intelligence

CVE-2026-76561: Dogtag PKI certificate profile import OS command injection

CVE-2026-76561 · Severity: high · CVSS 7.2 · Published 2026-09-08

Vendors: Red Hat.

Executive brief

Dogtag PKI is a certificate authority component used by FreeIPA to manage digital certificates for enterprise authentication. A flaw in its certificate profile import feature allows authenticated administrators to execute arbitrary system commands on the server. An attacker with CA Administrator access could gain complete control over the certificate authority infrastructure and the underlying host system.

Technical details

The vulnerability is an OS command injection (CWE-78) in Dogtag PKI's certificate profile import functionality. The vulnerable code does not properly validate or sanitize the content of uploaded certificate profiles beyond checking the profile ID, allowing exploitation of the ExternalProcessConstraint mechanism. An authenticated user with CA Administrator privileges can craft a malicious profile that executes arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account with further escalation to root observed in testing. The attack is network-reachable via the management API and requires valid CA Administrator credentials but no additional user interaction. Patches are not yet available; mitigation requires restricting CA Administrator role membership and auditing profile import operations.

Affected products

  • Dogtag PKI
  • Red Hat FreeIPA

Timeline

  • 2026-09-08: disclosed: CVE-2026-76561 published

References