CVE-2026-1709
Critical · CVSS 9.4keylime — TLS client authentication bypass (CWE-322)
- CVSS
- 9.4
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-322, NVD-CWE-noinfo, CWE-322
Description
A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing agents, retrieving public Trusted Platform Module (TPM) data, and deleting agents, by connecting without presenting a client certificate.
Search profile — drives PoC discovery
Symbols registrarclient certificateTLSmTLSssl_contextverify_modeCERT_NONECERT_OPTIONALCERT_REQUIREDlist agentsdelete agentsTPMtpm_pubagent_idregistrar_clientregistrar_servertornadossl.wrap_socketssl.SSLContext
Keywords CVE-2026-1709keylimekeylime registrarTLS authentication bypassclient certificate bypassunauthenticated registrarkeylime mTLS bypasskeylime agent delete unauthenticatedkeylime TPM data exposurekeylime 7.12.0keylime PoCkeylime exploit
Versions: >= 7.12.0
Affected packages
| PyPI | keylime | 0 → 7.12.0 |
| PyPI | keylime | 7.12.0 → 7.12.2 |
| PyPI | keylime | 7.13.0 → 7.13.1 |
References
- https://access.redhat.com/errata/RHSA-2026:2224
- https://access.redhat.com/errata/RHSA-2026:2225
- https://access.redhat.com/errata/RHSA-2026:2298
- https://access.redhat.com/security/cve/CVE-2026-1709
- https://bugzilla.redhat.com/show_bug.cgi?id=2435514
- https://access.redhat.com/errata/RHSA-2026:2224
- https://access.redhat.com/errata/RHSA-2026:2225
- https://access.redhat.com/errata/RHSA-2026:2298
- https://access.redhat.com/security/cve/CVE-2026-1709
- https://bugzilla.redhat.com/show_bug.cgi?id=2435514
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1709.json
Status: enriched · ingested 2026-06-27T06:00:38.000Z · profiled 2026-06-30T18:30:14.000Z