PT-2026-6781 · Keylime+1 · Keylime+1
Bzimport
·
Published
2026-02-06
·
Updated
2026-03-19
·
CVE-2026-1709
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Keylime versions 7.12.0 and later
Description
A flaw exists in Keylime where the registrar does not enforce client-side Transport Layer Security (TLS) authentication. This allows unauthenticated clients with network access to perform administrative operations. These operations include listing agents, retrieving public Trusted Platform Module (TPM) data, and deleting agents by connecting without presenting a client certificate.
Recommendations
Versions 7.12.0 and later require client-side TLS authentication to be enforced to prevent unauthorized administrative operations.
Fix
Improper Certificate Validation
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Keylime
Rocky Linux