Red Hat Fixes Dogtag PKI Profile Import Code Execution on RHEL 8

P1 — VALIDATE AND UPDATEHigh · 7.2 (official CVSS v3.1)EXPLOITATION: NOT STATED

Quick Answer

RHSA-2026:75573 fixes a High-severity Dogtag PKI profile-import flaw in the RHEL 8 pki-core:10.6 module. A CA Administrator or equivalent privileged user can cause code execution through crafted ExternalProcessConstraint content. Restrict profile-import access, review imports, and update.

Restrict Profile Import, Review Activity, And Update PKI

What to do now: Identify RHEL 8 CA systems using pki-core:10.6, limit CA Administrator and equivalent privileges, review recent certificate-profile imports and process activity, install the fixed module packages, and validate enrollment and issuance workflows.

Open the authoritative advisory

Last verified: 2026-10-05 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopeRHEL 8 pki-core:10.6 module and Red Hat Certificate System components
AdvisoryRHSA-2026:75573
CVECVE-2026-76561
Authoritative release date2026-10-05 03:17:53 UTC
Authority revision date2026-10-05 03:36:04 UTC
Affected versionsRHEL 8 pki-core:10.6 module content before the advisory-listed 10.15.1-3.module+el8.10.0+24994+a709cca8 packages.
Fixed versionpki-core 10.15.1-3.module+el8.10.0+24994+a709cca8 package set
CVSS base score7.2 (official CVSS v3.1)
CVSS severityHigh
Exploitation statusNot stated by Red Hat; no exploitation claim is inferred.

What Changed

Red Hat fixed CVE-2026-76561, which allows code execution during certificate-profile import when privileged content invokes an unsanitized ExternalProcessConstraint. Exploitation requires CA Administrator or equivalent profile-import privileges.

What To Validate Now

  1. Inventory. Locate RHEL 8 pki-core:10.6 module and Red Hat Certificate System components deployments, versions, enabled features, exposure paths, owners, and dependent services.
  2. Establish applicability. Confirm the pki-core:10.6 module and whether operators can import certificate profiles. Prioritize systems with multiple or delegated CA administrators; do not infer remote unauthenticated exposure.
  3. Remediate. Install the RHSA-2026:75573 pki-core:10.6 module package set, including pki-core 10.15.1-3.module+el8.10.0+24994+a709cca8, from the supported RHEL 8 AppStream channel.
  4. Validate. Confirm fixed packages, validate CA service health, profile import and certificate issuance, review audit and process-execution evidence, and ensure only approved roles retain profile-import privileges.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

Coordinate with PKI owners and preserve CA configuration, audit logs, imported profiles, and process telemetry before remediation. Restricting administrator roles is a risk-reduction measure, not the supported fix.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.