Vulnerability Description
Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Smallstep | Step-Ca | < 0.30.0 |
Related Weaknesses (CWE)
References
- https://github.com/smallstep/certificates/commit/e6da031d5125cfd99fe9a26f74bb41ePatch
- https://github.com/smallstep/certificates/releases/tag/v0.30.0-rc7Release Notes
- https://github.com/smallstep/certificates/security/advisories/GHSA-q4r8-xm5f-56gVendor Advisory
FAQ
What is CVE-2026-30836?
CVE-2026-30836 is a vulnerability with a CVSS score of 10.0 (CRITICAL). Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through ...
How severe is CVE-2026-30836?
CVE-2026-30836 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-30836?
Check the references section above for vendor advisories and patch information. Affected products include: Smallstep Step-Ca.