Red Hat Fixes Dogtag PKI Profile Import Code Execution on RHEL 8
Quick Answer
RHSA-2026:75573 fixes a High-severity Dogtag PKI profile-import flaw in the RHEL 8 pki-core:10.6 module. A CA Administrator or equivalent privileged user can cause code execution through crafted ExternalProcessConstraint content. Restrict profile-import access, review imports, and update.
Restrict Profile Import, Review Activity, And Update PKI
What to do now: Identify RHEL 8 CA systems using pki-core:10.6, limit CA Administrator and equivalent privileges, review recent certificate-profile imports and process activity, install the fixed module packages, and validate enrollment and issuance workflows.
Last verified: 2026-10-05 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | RHEL 8 pki-core:10.6 module and Red Hat Certificate System components |
|---|---|
| Advisory | RHSA-2026:75573 |
| CVE | CVE-2026-76561 |
| Authoritative release date | 2026-10-05 03:17:53 UTC |
| Authority revision date | 2026-10-05 03:36:04 UTC |
| Affected versions | RHEL 8 pki-core:10.6 module content before the advisory-listed 10.15.1-3.module+el8.10.0+24994+a709cca8 packages. |
| Fixed version | pki-core 10.15.1-3.module+el8.10.0+24994+a709cca8 package set |
| CVSS base score | 7.2 (official CVSS v3.1) |
| CVSS severity | High |
| Exploitation status | Not stated by Red Hat; no exploitation claim is inferred. |
What Changed
Red Hat fixed CVE-2026-76561, which allows code execution during certificate-profile import when privileged content invokes an unsanitized ExternalProcessConstraint. Exploitation requires CA Administrator or equivalent profile-import privileges.
What To Validate Now
- Inventory. Locate RHEL 8 pki-core:10.6 module and Red Hat Certificate System components deployments, versions, enabled features, exposure paths, owners, and dependent services.
- Establish applicability. Confirm the pki-core:10.6 module and whether operators can import certificate profiles. Prioritize systems with multiple or delegated CA administrators; do not infer remote unauthenticated exposure.
- Remediate. Install the RHSA-2026:75573 pki-core:10.6 module package set, including pki-core 10.15.1-3.module+el8.10.0+24994+a709cca8, from the supported RHEL 8 AppStream channel.
- Validate. Confirm fixed packages, validate CA service health, profile import and certificate issuance, review audit and process-execution evidence, and ensure only approved roles retain profile-import privileges.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
Coordinate with PKI owners and preserve CA configuration, audit logs, imported profiles, and process telemetry before remediation. Restricting administrator roles is a risk-reduction measure, not the supported fix.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

