What is CVE-2026-17039?
CVE-2026-17039 is a vulnerability in pki-core where the Certificate Authority (CA) renewal request path lacks the realm-based authorization check present in the enrollment path. This allows an authenticated user from one realm to renew a certificate belonging to a different realm. Affected systems should be updated to mitigate this issue.
Azərbaycanca: CVE-2026-17039 pki-core-də aşkar edilmiş zəiflikdir, burada Sertifikat Qurumu (CA) yeniləmə sorğusu yolu realm-əsaslı avtorizasiya yoxlaması aparmır. Bu, autentifikasiya olunmuş istifadəçiyə aid olmadığı realm-dəki sertifikatı yeniləməyə imkan verir. Təsirə məruz qalan sistemlərdə bu boşluğu aradan qaldırmaq üçün yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
In which operation does pki-core lack the realm-based authorization check?
The realm-based authorization check is missing in the Certificate Authority (CA) renewal request path, whereas it is present in the enrollment path.
What can an authenticated user do by exploiting CVE-2026-17039?
An authenticated user can renew a certificate belonging to a different realm.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.