CVE-2026-17039: Red Hat Certificate System 10
Low severity, CVSS 3.1. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization.
Affected products
- Red Hat Red Hat Certificate System 10
- Red Hat Red Hat Certificate System 11
- Red Hat Red Hat Certificate System 9
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
Published 2026-07-24. Last modified 2026-07-25.