Junglewise Threat Intelligence

Keylime registrar authentication bypass via missing TLS validation

Severity: low · CVSS 3.1 · Published 2026-02-06

Technologies: Keylime Project Keylime.

Executive brief

Keylime is a remote attestation and integrity measurement system that uses Trusted Platform Module (TPM) technology to verify the security of systems at boot and runtime. An authentication bypass vulnerability in the Keylime registrar component allows attackers on the network to perform critical administrative operations—such as listing managed systems, accessing sensitive TPM data, and deleting system records—without presenting valid credentials. This could allow attackers to manipulate the attestation process or gather intelligence on protected infrastructure.

Technical details

A flaw in the Keylime registrar (versions 7.12.0–7.13.0) fails to enforce mandatory client-side TLS authentication, allowing unauthenticated clients with network access to bypass authentication controls. The vulnerability stems from missing validation of client certificates during TLS handshake in the registrar service. An attacker can connect to the registrar endpoint over the network without presenting a valid client certificate and invoke privileged REST API endpoints to list agents, retrieve TPM public data, and delete agents from the system. The vulnerability was introduced in version 7.12.0 and fixed in 7.12.2 and 7.13.1. This is a critical authentication bypass affecting the core trust model of the attestation system.

Affected products

  • Keylime Project Keylime 7.12.0 through 7.12.1, 7.13.0

Timeline

  • 2026-02-06: disclosed
  • 2026-02-09: patched: Fixed in versions 7.12.2 and 7.13.1

References