PatchSiren cyber security CVE debrief
CVE-2026-18369 Red Hat CVE debrief
A flaw in Dogtag PKI's ACME responder allows unauthenticated ACME account holders to perform server-side request forgery (SSRF), causing the Dogtag server to send HTTP GET requests to internal network services. With the InMemory database backend, response bodies of internal targets are disclosed to the attacker through ACME challenge errors. This vulnerability can lead to potential disclosure of sensitive information and unauthorized access to internal network services. Defenders should assess exposure and prioritize verification and remediation efforts.
- Vendor
- Red Hat
- Product
- Red Hat Certificate System 10.4 EUS for RHEL-8
- CVSS
- MEDIUM 5.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-30
- Original CVE updated
- 2026-09-14
- Advisory published
- 2026-07-30
- Advisory updated
- 2026-09-14
Who should care
Defenders responsible for Dogtag PKI servers, especially those with the InMemory database backend, and internal network services that could be targeted via SSRF, should assess exposure and prioritize verification and remediation.
Why it matters
CVE-2026-18369 allows unauthenticated SSRF in Dogtag PKI's ACME responder, potentially disclosing internal target response bodies. Defenders should verify exposure, prioritize remediation, and apply Red Hat advisories.
- Potential disclosure of internal target response bodies with InMemory database backend
- SSRF vulnerability allowing access to internal network services
- Need for verification of Dogtag PKI server exposure and internal service targeting
- Priority on applying Red Hat errata and security advisories
Technical summary
The Dogtag PKI's ACME responder accepts IP address literals as DNS identifiers and follows HTTP redirects without validating the target is a public address. This allows unauthenticated ACME account holders to perform SSRF, potentially disclosing internal target response bodies with the InMemory database backend. The vulnerability can be exploited to send HTTP GET requests to internal network services, potentially leading to unauthorized access and disclosure of sensitive information. Defenders should prioritize verifying exposure of Dogtag PKI servers and assess internal network services that could be targeted via SSRF.
Defensive priority
Defenders should prioritize verifying exposure of Dogtag PKI servers, especially those with the InMemory database backend, and assess internal network services that could be targeted via SSRF.
Recommended defensive actions
- Verify Dogtag PKI server exposure, especially with InMemory database backend
- Assess internal network services that could be targeted via SSRF
- Review and apply Red Hat errata and security advisories related to this CVE
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the flaw in Dogtag PKI's ACME responder. Red Hat has provided references to errata and security advisories related to this CVE. The vulnerability allows unauthenticated SSRF, potentially disclosing internal target response bodies with the InMemory database backend. Evidence is limited to public sources, and defenders should verify exposure and apply Red Hat advisories.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-18369 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-18369
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-18369 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18369
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:67110
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-18369
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.