CRITICAL🇵🇱 Wersja polska

CVE-2026-1709

CVSS 9.4v3.1pub. 2026-02-06upd. 2026-06-27

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing agents, retrieving public Trusted Platform Module (TPM) data, and deleting agents, by connecting without presenting a client certificate.

🤖 AI Analysis
How it works

Keylime Registrar starting from version 7.12.0 stopped enforcing client-side authentication in Transport Layer Security (TLS) protocol. In proper configuration, the client should present a client certificate when establishing a connection, which confirms its identity. Due to this vulnerability (CWE-322: Key Exchange without Entity Authentication), any client with network access can establish a connection without a certificate and perform operations reserved for authenticated entities.

Impact

An unauthenticated attacker with network access can enumerate agents, read public Trusted Platform Module (TPM) data, and delete agents, threatening the integrity and availability of the trust verification infrastructure.

Mitigation & patch

Apply patches available from the vendor according to Red Hat advisories: RHSA-2026:2224, RHSA-2026:2225, and RHSA-2026:2298. Additionally, until updates are applied, it is recommended to restrict network access to Keylime Registrar only to trusted hosts using firewall or network segmentation.

Who is affected

Keylime version 7.12.0 and later; Red Hat Enterprise Linux, Red Hat Enterprise Linux EUS, and Red Hat Enterprise Linux for ARM 64 (versions indicated in vendor references)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
  • Keylime

    APP
    Keylime
    < 7.12.0
  • Red Hat Enterprise Linux

    OS
    Redhat
    10.09.0
  • Red Hat Enterprise Linux Eus

    OS
    Redhat
    10.0
  • Red Hat Enterprise Linux For Arm 64

    OS
    Redhat
    10.0_aarch649.0_aarch64
  • Red Hat Enterprise Linux For Arm 64 Eus

    OS
    Redhat
    10.0_aarch64
  • Red Hat Enterprise Linux For IBM Z Systems

    OS
    Redhat
    10.0_s390x9.0_s390x
  • Red Hat Enterprise Linux For IBM Z Systems Eus

    OS
    Redhat
    10.0_s390x
  • Red Hat Enterprise Linux For Power Little Endian

    OS
    Redhat
    10.0_ppc64le9.0_ppc64le
  • Red Hat Enterprise Linux For Power Little Endian Eus

    OS
    Redhat
    10.0_ppc64le
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)

CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product

SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego

CVE-2019-5544CRITICAL9.8⚠ KEVPL ✓same product

Krytyczny heap overwrite w OpenSLP dla VMware ESXi i Horizon DaaS

CVE-2018-14667CRITICAL9.8⚠ KEVPL ✓same product

RCE przez EL injection w RichFaces Framework 3.X — brak uwierzytelnienia

CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓same product

Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX