REDHAT-BUG-2481893: Low severity Unknown Root CA key update Certificate Management Protocol (CMP) message response vulnerability
An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation of credentials from the Registration Authority (RA) level to the root Certification Authority (root CA) level.
Affected Software
Event History
Frequently Asked Questions
What access would an attacker need to exploit this issue?
The issue could allow escalation from Registration Authority (RA) credentials to root Certification Authority (root CA) credentials. The available information does not describe an unauthenticated attack path.
Which systems or workflows are exposed?
Exposure is associated with Root CA key update Certificate Management Protocol (CMP) message responses that use the affected certificate-verification callback. The provided data does not identify specific products, versions, or default configurations.
How can I determine whether an environment is affected?
Review systems that process Root CA key update CMP responses and check whether they are covered by RHSA-2026:25237 or RHSA-2026:25239. The supplied information does not provide a configuration check or indicator of prior exploitation.