RHSA-2026:75573HighCVSS 7.2

Red Hat Security Advisory: pki-core:10.6 security update

Published
October 5, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-76561 — pki-core: Dogtag/PKI: certprofile-import allows code execution via unsanitized profile content (ExternalProcessConstraint)

🎯 Affected products58

  • Red Hat Enterprise Linux AppStream (v. 8)
  • idm-jss-0:4.11.0-1.module+el8.10.0+21280+cce842b8.aarch64 (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-jss-0:4.11.0-1.module+el8.10.0+21280+cce842b8.ppc64le (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-jss-0:4.11.0-1.module+el8.10.0+21280+cce842b8.s390x (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-jss-0:4.11.0-1.module+el8.10.0+21280+cce842b8.x86_64 (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-jss-debuginfo-0:4.11.0-1.module+el8.10.0+21280+cce842b8.aarch64 (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-jss-debuginfo-0:4.11.0-1.module+el8.10.0+21280+cce842b8.ppc64le (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-jss-debuginfo-0:4.11.0-1.module+el8.10.0+21280+cce842b8.s390x (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-jss-debuginfo-0:4.11.0-1.module+el8.10.0+21280+cce842b8.x86_64 (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-jss-javadoc-0:4.11.0-1.module+el8.10.0+21280+cce842b8.aarch64 (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-jss-javadoc-0:4.11.0-1.module+el8.10.0+21280+cce842b8.ppc64le (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-jss-javadoc-0:4.11.0-1.module+el8.10.0+21280+cce842b8.s390x (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-jss-javadoc-0:4.11.0-1.module+el8.10.0+21280+cce842b8.x86_64 (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-ldapjdk-0:4.24.0-1.module+el8.10.0+21280+cce842b8.noarch (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-ldapjdk-javadoc-0:4.24.0-1.module+el8.10.0+21280+cce842b8.noarch (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-pki-acme-0:10.15.1-3.module+el8.10.0+24994+a709cca8.noarch (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-pki-base-0:10.15.1-3.module+el8.10.0+24994+a709cca8.noarch (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-pki-base-java-0:10.15.1-3.module+el8.10.0+24994+a709cca8.noarch (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-pki-ca-0:10.15.1-3.module+el8.10.0+24994+a709cca8.noarch (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-pki-kra-0:10.15.1-3.module+el8.10.0+24994+a709cca8.noarch (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-pki-server-0:10.15.1-3.module+el8.10.0+24994+a709cca8.noarch (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-pki-symkey-0:10.15.1-3.module+el8.10.0+24994+a709cca8.aarch64 (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-pki-symkey-0:10.15.1-3.module+el8.10.0+24994+a709cca8.ppc64le (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-pki-symkey-0:10.15.1-3.module+el8.10.0+24994+a709cca8.s390x (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-pki-symkey-0:10.15.1-3.module+el8.10.0+24994+a709cca8.x86_64 (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-pki-symkey-debuginfo-0:10.15.1-3.module+el8.10.0+24994+a709cca8.aarch64 (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-pki-symkey-debuginfo-0:10.15.1-3.module+el8.10.0+24994+a709cca8.ppc64le (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-pki-symkey-debuginfo-0:10.15.1-3.module+el8.10.0+24994+a709cca8.s390x (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-pki-symkey-debuginfo-0:10.15.1-3.module+el8.10.0+24994+a709cca8.x86_64 (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • idm-pki-tools-0:10.15.1-3.module+el8.10.0+24994+a709cca8.aarch64 (pki-core:10.6) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • +28 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Until a fixed package is available, restrict membership in CA Administrator and equivalent roles to fully trusted operators, and audit certificate profile import operations for unexpected or unrecognized profile content. Review any custom ExternalProcessConstraint executable configuration in Dogtag for unnecessary exposure.

🔗 References (4)