CVE-2026-1709: Keylime

Critical severity, CVSS 9.8. EPSS: 5.8% chance of exploitation in the next 30 days.

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing agents, retrieving public Trusted Platform Module (TPM) data, and deleting agents, by connecting without presenting a client certificate.

Affected products

  • Keylime Keylime: before 7.12.0 (fixed in 7.12.0)
  • Red Hat Enterprise Linux: version 9.0 only; version 10.0 only
  • Red Hat Enterprise Linux Eus: version 10.0 only
  • Red Hat Enterprise Linux For Arm 64: version 9.0_aarch64 only; version 10.0_aarch64 only
  • Red Hat Enterprise Linux For Arm 64 Eus: version 10.0_aarch64 only
  • Red Hat Enterprise Linux For IBM Z Systems: version 9.0_s390x only; version 10.0_s390x only
  • Red Hat Enterprise Linux For IBM Z Systems Eus: version 10.0_s390x only
  • Red Hat Enterprise Linux For Power Little Endian: version 9.0_ppc64le only; version 10.0_ppc64le only
  • Red Hat Enterprise Linux For Power Little Endian Eus: version 10.0_ppc64le only

Published 2026-02-06. Last modified 2026-07-15.