cbcvebase.
CVE-2026-1709
published 2026-02-06

CVE-2026-1709: A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing agents, retrieving public Trusted Platform Module (TPM) data, and deleting agents, by connecting without presenting a client certificate.

Affected

15 ranges
VendorProductVersion rangeFixed in
keylimekeylime< 7.12.07.12.0
keylimekeylime>= 7.12.0 < 7.12.27.12.2
keylimekeylime>= 7.13.0 < 7.13.17.13.1
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_eus
redhatenterprise_linux_for_arm_64
redhatenterprise_linux_for_arm_64
redhatenterprise_linux_for_arm_64_eus
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems_eus
redhatenterprise_linux_for_power_little_endian
redhatenterprise_linux_for_power_little_endian
redhatenterprise_linux_for_power_little_endian_eus