CVE-2026-30836

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.
Configurations

No configuration.

History

No history.

Information

Published : 2026-03-19 21:17

Updated : 2026-03-20 13:39


NVD link : CVE-2026-30836

Mitre link : CVE-2026-30836

CVE.ORG link : CVE-2026-30836


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication

CWE-295

Improper Certificate Validation