PT-2026-26343 · Step Ca · Step Ca
Prasanthsundararajan69
·
Published
2026-03-19
·
Updated
2026-04-27
·
CVE-2026-30836
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Step CA versions 0.30.0-rc6 and below
Description
Step CA is an online certificate authority designed for secure, automated certificate management. A flaw exists where the software does not adequately protect against unauthenticated certificate issuance through the SCEP UpdateReq (MessageType=18). This allows attackers to potentially obtain valid certificates for any domain without providing credentials. The
SCEP UpdateReq bypasses all authentication checks within Step CA.Recommendations
Versions prior to 0.30.0 should be upgraded to version 0.30.0.
Exploit
Fix
Improper Certificate Validation
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Step Ca