← Database

CVE-2026-53682

MEDIUM CVSS: 5.3 Published: 2026-09-01 Modified: 2026-09-01

Description

An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session.

Affected Platforms

Unknown

Weakness Type

CWE-200, CWE-284

References