CVE-2026-17039: Red Hat Certificate System 10

Low severity, CVSS 3.1. EPSS: 0.3% chance of exploitation in the next 30 days.

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization.

Affected products

  • Red Hat Red Hat Certificate System 10
  • Red Hat Red Hat Certificate System 11
  • Red Hat Red Hat Certificate System 9
  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9

Published 2026-07-24. Last modified 2026-07-25.