CVE-2026-30836: Smallstep Step-Ca

Critical severity, CVSS 10.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.

Affected products

  • Smallstep Step-Ca: before 0.30.0 (fixed in 0.30.0); version 0.30.0 only

Published 2026-03-19. Last modified 2026-06-17.