CVE-2026-30836
EUVD-2026-1320019.03.2026, 21:17
Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| smallstep | step-ca | 𝑥 < 0.30.0 |
| smallstep | step-ca | 0.30.0:rc1 |
| smallstep | step-ca | 0.30.0:rc2 |
| smallstep | step-ca | 0.30.0:rc3 |
| smallstep | step-ca | 0.30.0:rc4 |
| smallstep | step-ca | 0.30.0:rc5 |
| smallstep | step-ca | 0.30.0:rc6 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration