CVE-2026-42769: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate
An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation of credentials from the Registration Authority (RA) level to the root Certification Authority (root CA) level.
Other sources
Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u1Fixed in 1.1.1w-0+deb11u7Fixed in 3.0.20-1~deb12u1Fixed in 3.0.20-1~deb12u2Fixed in 3.5.6-1~deb13u2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.3.7-4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42769?
The severity of CVE-2026-42769 is rated as medium with a CVSS score of 5.3.
How do I fix CVE-2026-42769?
To fix CVE-2026-42769, upgrade to the latest patched version of OpenSSL that addresses this vulnerability.
What type of vulnerability is CVE-2026-42769?
CVE-2026-42769 is a Trust-Anchor Substitution vulnerability that affects the certificate validation process.
Which software is affected by CVE-2026-42769?
CVE-2026-42769 affects OpenSSL and specifically Debian's implementation of OpenSSL.
What can be the consequences of CVE-2026-42769?
CVE-2026-42769 can lead to the escalation of credentials from the Registration Authority level to the root Certificate level.