---
cve: "CVE-2026-76561"
severity: "HIGH"
cvss: 7.2
epss: "0.6%"
vendor: "Red Hat"
kev: false
exploited: false
published: "2026-09-08 08:17:12"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-10-01T13:29:54+02:00"
---

# CVE-2026-76561

> 7.2 HIGH

## Beschreibung

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account.

## CNA-Record (Kanon, cvelistV5)

- CNA: **redhat**
- State: PUBLISHED
- Stand: 2026-09-30 14:44:38
- CNA-CVSS: **7.2** (`CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **total**

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## BSI-Hinweise (deutsch)

- [Red Hat Enterprise Linux (pki-core und dogtag-pki): Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3662) — _BSI-Einstufung: hoch_
  Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux (pki-core und dogtag-pki) ausnutzen, um beliebigen Programmcode auszuführen, und um Daten zu manipulieren.

## Referenzen

- <https://access.redhat.com/errata/RHSA-2026:73765>
- <https://access.redhat.com/errata/RHSA-2026:73766>
- <https://access.redhat.com/security/cve/CVE-2026-76561>
- <https://bugzilla.redhat.com/show_bug.cgi?id=2519523>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-76561) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
