PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-25825 Keyfactor CVE debrief

CVE-2026-25825 is a low-severity vulnerability in Keyfactor SignServer before version 7.6.0. An admin user can exploit this issue to write files to arbitrary directories in the server filesystem, potentially overwriting files accessible by the local user JBoss. This vulnerability allows for unauthorized file writes, which could lead to further exploitation. Defenders should assess exposure and prioritize verification and remediation efforts. The vulnerability has a CVSS score of 2.7 and is considered low-severity.

Vendor
Keyfactor
Product
SignServer
CVSS
LOW 2.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-22
Advisory published
2026-09-15
Advisory updated
2026-09-22

Who should care

Defenders responsible for Keyfactor SignServer deployments should assess exposure and prioritize verification and remediation efforts. This includes reviewing the current version of Keyfactor SignServer, restricting admin access, and monitoring for suspicious file writes. Defenders should also consider the potential operational impacts of this vulnerability, including potential unauthorized file writes and possible overwrite of files accessible by the JOSS

Why it matters

CVE-2026-25825 is a low-severity vulnerability in Keyfactor SignServer that allows an admin user to write files to arbitrary directories in the server filesystem. Defenders should prioritize verifying and upgrading to version 7.6.0 or later, and restrict admin access to minimize potential impact.

  • Potential unauthorized file writes in the server filesystem
  • Possible overwrite of files accessible by the local user JBoss
  • Requires verification of Keyfactor SignServer version and admin access controls
  • Remediation priority for Keyfactor SignServer deployments

Technical summary

The vulnerability allows an admin user to write files to arbitrary directories in the server filesystem, potentially overwriting files accessible by the local user JBoss. This could lead to further exploitation and unauthorized file writes. The vulnerability is considered low-severity with a CVSS score of 2.7. Defenders should prioritize verifying and upgrading to Keyfactor SignServer version 7.6.0 or later, and restrict admin access to minimize potential impact. The vulnerability has a CVSS score of 2.7 and is considered low-severity.

Defensive priority

Defenders should prioritize verifying and upgrading to Keyfactor SignServer version 7.6.0 or later, and restrict admin access to minimize potential impact.

Recommended defensive actions

  • Verify and upgrade to Keyfactor SignServer version 7.6.0 or later
  • Restrict admin access to minimize potential impact
  • Monitor for suspicious file writes in the server filesystem
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. Keyfactor's official support page may offer additional details. The vulnerability was disclosed on 2026-09-15T15:17:14.347Z. The NVD entry and CVE record provide some context, but further verification is needed to understand the full scope of the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-25825 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-25825

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-25825 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-25825

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.