CVE-2026-77707: TLS Certificate Validation Disabled for Keycloak Connections in HAVELSAN's Liman Render Engine
Improper certificate validation vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM).
This issue affects Liman Render Engine: from 1.0 before 1.2-75.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Liman Render Engineto a version that resolves this vulnerability.Fixed in 1.2-75
Event History
Frequently Asked Questions
Which deployments are affected?
HAVELSAN Liman Render Engine versions from 1.0 up to, but not including, 1.2-75 are affected.
What does an attacker need to exploit this issue?
An attacker must be able to act as an adversary in the middle of a connection to Keycloak. The CVSS vector indicates exploitation is network-based, requires no privileges or user interaction, but has high attack complexity.
What is the security impact of successful exploitation?
Successful exploitation can expose confidential information. The reported vector indicates no direct integrity or availability impact.