CVE-2026-1709
A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing agents, retrieving public Trusted Platform Module (TPM) data, and deleting agents, by connecting without presenting a client certificate.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.4
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
- EPSS probability
- 5.53%
- CWE
- CWE-322
- Published
- 2026-02-06
- Last modified
- 2026-07-15
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support
- Red Hat Red Hat Enterprise Linux 9
Weakness type
Related vulnerabilities
- CVE-2026-18654 — Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
- CVE-2026-58065 — Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification
- CVE-2026-45361 — Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)
- CVE-2026-44467 — Claude Desktop: SSH Host Key Verification Bypass Allows Man-in-the-Middle Attack on Remote Sessions
- CVE-2026-1354 — Zero Motorcycles Firmware Key Exchange without Entity Authentication
- CVE-2025-13914 — Apstra: SSH host key validation vulnerability for managed devices
- CVE-2026-33697 — CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys
- CVE-2025-62501 — SSH Hostkey Misconfiguration Vulnerability in TP-Link Archer AX53