CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-18047

mediumCVSS 6.5covered by 1 sourcefirst seen 2026-07-28
A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker can bypass the Tomcat authentication constraint while RESTEasy still routes the request to the handler, allowing unauthorized toggling of the ACME service state including persistent denial of service.

⚡ Watch CVE-2026-18047

Get an email if CVE-2026-18047 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-18047

CVE.org record

Embed the live status

CVE-2026-18047 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-18047 status](https://www.csirts.com/badge/CVE-2026-18047)](https://www.csirts.com/cve/CVE-2026-18047)