CVE-2026-30836

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:smallstep:step-ca:*:*:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc1:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc2:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc3:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc4:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc5:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc6:*:*:*:go:*:*

History

27 Apr 2026, 13:41

Type Values Removed Values Added
Summary
  • (es) Step CA es una autoridad de certificación en línea para la gestión de certificados segura y automatizada para DevOps. Las versiones 0.30.0-rc6 e inferiores no protegen contra la emisión de certificados no autenticada a través de la solicitud SCEP UpdateReq. Este problema ha sido corregido en la versión 0.30.0.
First Time Smallstep
Smallstep step-ca
References () https://github.com/smallstep/certificates/commit/e6da031d5125cfd99fe9a26f74bb41e4dacca4ef - () https://github.com/smallstep/certificates/commit/e6da031d5125cfd99fe9a26f74bb41e4dacca4ef - Patch
References () https://github.com/smallstep/certificates/releases/tag/v0.30.0-rc7 - () https://github.com/smallstep/certificates/releases/tag/v0.30.0-rc7 - Release Notes
References () https://github.com/smallstep/certificates/security/advisories/GHSA-q4r8-xm5f-56gw - () https://github.com/smallstep/certificates/security/advisories/GHSA-q4r8-xm5f-56gw - Vendor Advisory
CPE cpe:2.3:a:smallstep:step-ca:0.30.0:rc5:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc6:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc3:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc2:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:*:*:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc1:*:*:*:go:*:*
cpe:2.3:a:smallstep:step-ca:0.30.0:rc4:*:*:*:go:*:*

19 Mar 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-19 21:17

Updated : 2026-04-27 13:41


NVD link : CVE-2026-30836

Mitre link : CVE-2026-30836

CVE.ORG link : CVE-2026-30836


JSON object : View

Products Affected

smallstep

  • step-ca
CWE
CWE-287

Improper Authentication

CWE-295

Improper Certificate Validation