All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-30836
CRITICALpublished 2026-03-19 21:17 UTC · 5 months ago · modified 2026-06-17 10:33 UTC
10.0
CVSS / 10
// description
Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.
// weaknesses (CWE)
- CWE-287
- CWE-295