PT-2025-52670 · Keyfactor · Keyfactor Signserver
Published
2025-12-22
·
Updated
2026-01-05
·
CVE-2025-26787
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Keyfactor SignServer versions prior to 7.2
Description
A flaw exists in the startup logic of the Keyfactor SignServer container. The Admin CLI command, designed to configure certificate access during the initial container startup, incorrectly runs on each container restart. This resets the configuration to allow any user with a valid and trusted client authentication certificate to connect, overriding any more restrictive access settings configured by administrators.
Recommendations
Update to a version that is not prior to 7.2.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keyfactor Signserver