← All Advisories

CVE-2026-80110

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-80110

Key Details

CVECVE-2026-80110
CVSS Score / Version8.1 (High) / CVSS v3.1
Updated2026-09-30
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productsRed Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, and Red Hat Enterprise Linux 9
Classified asCWE-863 (Incorrect Authorization)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
SubsystemsOT Supporting Infrastructure
SectorsMultiple

What to Know

A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to override a more specific literal-mapped permission when both match. In the CA's profile-management REST API this allows a request to POST /v2/profiles/raw -- intended to require Administrator-level profiles.create permission -- to instead be authorized under the lower-privileged profiles.approve permission held by the default Certificate Manager Agents group. The highest threat from this vulnerability is to confidentiality and integrity of the certificate authority's issuance policy. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-80110
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-80110