U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2026-18047

Change History

New CVE Received from Red Hat, Inc. 7/28/2026 9:17:36 AM

Action Type Old Value New Value
Added Description

                  
                
              
A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker can bypass the Tomcat authentication constraint while RESTEasy still routes the request to the handler, allowing unauthorized toggling of the ACME service state including persistent denial of service.
Added CVSS V3.1

                  
                
              
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Added CWE

                  
                
              
CWE-288
Added Reference

                  
                
              
https://access.redhat.com/security/cve/CVE-2026-18047
Added Reference

                  
                
              
https://bugzilla.redhat.com/show_bug.cgi?id=2507956
Added Affected

                  
                
              
[{"vendor":"Red Hat","product":"Red Hat Certificate System 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redhat-pki:10/redhat-pki","cpes":["cpe:/a:redhat:certificate_system:10"]},{"vendor":"Red Hat","product":"Red Hat Certificate System 11","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redhat-pki","cpes":["cpe:/a:redhat:certificate_system:11"]},{"vendor":"Red Hat","product":"Red Hat Certificate System 9","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"pki-core","cpes":["cpe:/a:redhat:certificate_system:9"]},{"vendor":"Red Hat","product":"Red Hat Certificate System 9","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redhat-pki","cpes":["cpe:/a:redhat:certificate_system:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dogtag-pki","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"pki-core","cpes":["cpe:/o:redhat:enterprise_linux:6"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"pki-core","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"pki-core:10.6/pki-core","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"pki-core","cpes":["cpe:/o:redhat:enterprise_linux:9"]}]