Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ CVE-2026-1709 — enterprise-linux

🔴 CVSS 9.5 — Critical ✅ No Known Exploit CWE-322 NVD
9.5
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Keylime Missing Authentication for Critical Function and Improper Authentication

Impact

The Keylime registrar does not enforce mutual TLS (mTLS) client certificate authentication since version 7.12.0. The registrar's TLS context is configured with ssl.CERT_OPTIONAL instead of ssl.CERT_REQUIRED, allowing any client to connect to protected API endpoints without presenting a valid client certificate.

Who is impacted:

  • All Keylime deployments running versions 7.12.0 through 7.13.0
  • Environments where the registrar HTTPS port (default 8891) is network-accessible to untrusted clients

What an attacker can do:

  • List all registered agents (GET /v2/agents/) - enumerate the entire agent inventory
  • Retrieve agent details (GET /v2/agents/{uuid}) - obtain public TPM keys, certificates, and network locations (IP/port) of any agent
  • Delete any agent (DELETE /v2/agents/{uuid}) - remove agents from the registry, disrupting attestation services

Note: The exposed TPM data (EK, AK, certificates) consists of public keys and certificates. Private keys remain protected within TPM hardware. The HMAC secret used for challenge-response validation is stored in the database but is not exposed via the API.

Affected versions: >= 7.12.0, <= 7.13.0

Fixed versions: 7.12.2, >= 7.13.1

Patches

A patch for the affected released versions is available. It removes the line that override the configuration of ssl.verify_mode, leaving the CERT_REQUIRED value set by web_util.init_mtls():

```diff

diff --git a/keylime/web/base/server.py b/keylime/web/base/server.py

index 1d9a9c2..859b23a 100644

--- a/keylime/web/base/server.py

+++ b/keylime/web/base/server.py

@@ -2,7 +2,6 @@ import asyncio

import multiprocessing

from abc import ABC, abstractmethod

from functools import wraps

-from ssl import CERT_OPTIONAL

from typing import TYPE_CHECKING, Any, Callable, Optional

import tornado

@@ -252,7 +251,6 @@ class Server(ABC):

self._https_port = config.getint(component, "tls_port", fallback=0)

self._max_upload_size = config.getint(component, "max_upload_size", fallback=104857600)

self._ssl_ctx = web_util.init_mtls(component)

  • self._ssl_ctx.verify_mode = CERT_OPTIONAL

def _get(self, pattern: str, controller: type["Controller"], action: str, allow_insecure: bool = False) -> None:

"""Creates a new route to handle incoming GET requests issued for paths which match the given

```

Users should upgrade to the patched version once it is released.

Workarounds

If upgrading is not immediately possible, apply one of the following mitigations:

1. Network isolation (Recommended)

Restrict access to the registrar HTTPS port (default 8891) using firewall rules

to allow only trusted hosts (verifier, tenant):

Example using iptables

```

iptables -A INPUT -p tcp --dport 8891 -s <verifier_ip> -j ACCEPT

iptables -A INPUT -p tcp --dport 8891 -s <tenant_ip> -j ACCEPT

iptables -A INPUT -p tcp --dport 8891 -j DROP

```

2. Reverse proxy with mTLS enforcement

Deploy a reverse proxy (nginx, HAProxy) in front of the registrar that enforces client certificate authentication:

Example nginx configuration

```

server {

listen 8891 ssl;

ssl_certificate /path/to/server.crt;

ssl_certificate_key /path/to/server.key;

ssl_client_certificate /path/to/ca.crt;

ssl_verify_client on; # Enforce client certificates

location / {

proxy_pass https://localhost:8892; # Internal registrar port

}

}

```

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality low, integrity high, availability high.

CVSS metrics in full

The score comes from this vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

  • Attack vector: Network — reachable from anywhere that can route to the service.
  • Attack complexity: Low — the attack works reliably, with no preparation.
  • Privileges required: None — an unauthenticated stranger can try it.
  • User interaction: None — nobody has to be tricked into anything.
  • Scope: Unchanged — the damage stays inside the vulnerable component.
  • Confidentiality impact: Low — limited, and the attacker does not choose what is affected.
  • Integrity impact: High — total loss, or loss the attacker controls.
  • Availability impact: High — total loss, or loss the attacker controls.

Weakness class

CVE-2026-1709 is classified as CWE-322: Key Exchange without Entity Authentication. The product performs a key exchange with an actor without verifying the identity of that actor.

Affected software

CVE-2026-1709 is recorded against 9 packages.

  • enterprise-linux
  • enterprise-linux-eus
  • enterprise-linux-for-arm-64
  • enterprise-linux-for-arm-64-eus
  • enterprise-linux-for-ibm-z-systems
  • enterprise-linux-for-ibm-z-systems-eus
  • enterprise-linux-for-power-little-endian
  • enterprise-linux-for-power-little-endian-eus
  • keylime (fixed in 7.12.0)

Timeline and source

Published on 6 February 2026 and last revised on 15 July 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

access.redhat.com
access.redhat.com
access.redhat.com
access.redhat.com
bugzilla.redhat.com
access.redhat.com
access.redhat.com
access.redhat.com
access.redhat.com
bugzilla.redhat.com
security.access.redhat.com

Other advisories for this package

enterprise-linux has other advisories on record. If you are patching this one, these are worth checking on the same host:

Same weakness in other software

These advisories are the same class of weakness (CWE-322: Key Exchange without Entity Authentication) in other software:

Details

Severity CRITICAL
CVSS Score 9.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
CWE CWE-322
Public Exploit ✅ No
Source NVD
Published 2026-02-06
Updated 2026-08-20
Modified 2026-07-15
Fix URL N/A

Affected Packages

Software From version Fixed in
enterprise-linux
enterprise-linux-eus
enterprise-linux-for-arm-64
enterprise-linux-for-arm-64-eus
enterprise-linux-for-ibm-z-systems
enterprise-linux-for-ibm-z-systems-eus
enterprise-linux-for-power-little-endian
enterprise-linux-for-power-little-endian-eus
keylime 7.12.0

References

Issue Tracking, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=2435514
Issue Tracking, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=2435514

Similar Threats

Exploit Protection

Are you running enterprise-linux?

CVE-2026-1709 carries CVSS 9.5 Critical rating. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.

Check My Site For CVE-2026-1709 →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2026