CRITICAL · 9.4

CVE-2026-1709

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows un...

Vulnerability Description

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing agents, retrieving public Trusted Platform Module (TPM) data, and deleting agents, by connecting without presenting a client certificate.

CVSS Score

9.4

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
KeylimeKeylime< 7.12.0
RedhatEnterprise Linux9.0
RedhatEnterprise Linux Eus10.0
RedhatEnterprise Linux For Arm 649.0_aarch64
RedhatEnterprise Linux For Arm 64 Eus10.0_aarch64
RedhatEnterprise Linux For Ibm Z Systems9.0_s390x
RedhatEnterprise Linux For Ibm Z Systems Eus10.0_s390x
RedhatEnterprise Linux For Power Little Endian9.0_ppc64le
RedhatEnterprise Linux For Power Little Endian Eus10.0_ppc64le

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-1709?

CVE-2026-1709 is a vulnerability with a CVSS score of 9.4 (CRITICAL). A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows un...

How severe is CVE-2026-1709?

CVE-2026-1709 has been rated CRITICAL with a CVSS base score of 9.4/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2026-1709?

Check the references section above for vendor advisories and patch information. Affected products include: Keylime Keylime, Redhat Enterprise Linux, Redhat Enterprise Linux Eus, Redhat Enterprise Linux For Arm 64, Redhat Enterprise Linux For Arm 64 Eus.