CVE-2026-25825: Keyfactor SignServer vulnerability
An issue was discovered in Keyfactor SignServer before 7.6.0. The output file to which SignerStatusReportWorker logs the report can be set to any path, even one that points to a file that already exists. This gives a user (with admin access) the possibility to write files in arbitrary directories in the server filesystem and potentially overwrite files accessible by the local user JBoss.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires admin access to SignServer. The attacker can configure the SignerStatusReportWorker report output path to target arbitrary locations on the server filesystem.
What is the practical impact of the arbitrary file write?
An administrator can write report output into arbitrary directories and may overwrite existing files that are accessible to the local JBoss user. The impact therefore depends on which files and directories that account can access.
Which versions are affected?
The issue affects Keyfactor SignServer versions before 7.6.0.
How can I determine whether a system may have been targeted?
Review SignerStatusReportWorker configuration and report output locations for paths outside intended report directories, especially paths pointing to existing files. Also examine files writable by the local JBoss user for unexpected report content or modifications.