peter bassill · operator
$ cve CVE-2026-1709 JSON

CVE-2026-1709

9.4
CRITICAL · CVSS 3.1 · EPSS 5.8% (pctl 93)

In your normal cycle

Critical by CVSS (9.4), but no sign of active exploitation.

Description

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing agents, retrieving public Trusted Platform Module (TPM) data, and deleting agents, by connecting without presenting a client certificate.

Scoring

CVSS9.4 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
EPSS5.79% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-322
On CISA KEVno
Public exploitnone known
Published2026-02-06
Last modified2026-07-15

Affected (9)

VendorProduct
keylimekeylime
redhatenterprise linux
redhatenterprise linux eus
redhatenterprise linux for arm 64
redhatenterprise linux for arm 64 eus
redhatenterprise linux for ibm z systems
redhatenterprise linux for ibm z systems eus
redhatenterprise linux for power little endian
redhatenterprise linux for power little endian eus

References

→ the Explorer  ·  watch your stack  ·  NVD