cvedb.io
CVE-2021-40088
MEDIUM · CVSS 5.4
EPSS exploitation probability: 0%
Published 2021-08-25T02:15:08.230 · Last modified 2026-06-17T04:06:29.983

Summary

An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certificate is used for revocation requests as well. While enrollment enforces multi tenancy constraints (by verifying that the client certificate has access to the CA and Profiles being enrolled against), this check was not performed when authenticating revocation operations, allowing a known tenant to revoke a certificate belonging to another tenant.

Affected products

primekey — ejbca

Does this affect you?

Add your gear to cvedb and we'll alert you only when primekey ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.