What is CVE-2026-18047?
This flaw in Dogtag PKI's ACME responder stems from the web.xml security constraints using exact URL pattern matching for admin-only endpoints. An unauthenticated attacker can bypass Tomcat's authentication constraint by appending a trailing slash to the URL, potentially accessing enable/disable operations. Updating Dogtag PKI to the latest patched version is strongly recommended.
Azərbaycanca: Dogtag PKI-nin ACME responder-da aşkarlanan bu boşluq 'web.xml' faylında təhlükəsizlik məhdudiyyətlərinin yalnız dəqiq URL uyğunluğundan istifadə etməsi ilə bağlıdır. Sonuna slash işarəsi əlavə etməklə autentifikasiya olunmamış hücumçu admin əməliyyatlarını (enable/disable) məhdudiyyəti keçərək icra edə bilər. Bu problemi aradan qaldırmaq üçün Dogtag PKI-ni ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ1
How can the CVE-2026-18047 vulnerability in Dogtag PKI be exploited?
This flaw stems from the web.xml security constraints using exact URL pattern matching for admin-only endpoints. An unauthenticated attacker can bypass the authentication constraint and execute operations like enable/disable by appending a trailing slash to the intended admin URL.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.