CVE-2026-1709Disclosure(keylime / enterprise_linux)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch keylime enterprise_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing agents, retrieving public Trusted Platform Module (TPM) data, and deleting agents, by connecting without presenting a client certificate.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-322

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • enterprise_linux_eus
  • enterprise_linux_for_arm_64
  • enterprise_linux_for_arm_64_eus

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-06); latest day: 2
  • 7 total mentions across 3 days

Affected systems

Products
enterprise_linuxenterprise_linux_eusenterprise_linux_for_arm_64enterprise_linux_for_arm_64_eusenterprise_linux_for_ibm_z_systemsenterprise_linux_for_ibm_z_systems_eusenterprise_linux_for_power_little_endianenterprise_linux_for_power_little_endian_euskeylime

8 versions affected across 9 products

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-02-06: 4Mentions · 2026-02-11: 1Mentions · 2026-03-04: 2Patch / Workaround · 2026-03-04: 2Technical Details · 2026-02-06: 402-0602-1103-04
Signal classification3 categories
Disclosure
342.9%
General
228.6%
Patch
228.6%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-064
Disclosure3General1
2026-02-111
General1
2026-03-042
Patch2
Full discourse7 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-1709 A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authenticatio… https://www.cve.org/CVERecord?id=CVE-2026-1709

    Post summary

    The Keylime registrar, from version 7.12.0 onward, lacks client-side TLS authentication enforcement, revealing CVE‑2026‑1709.

    00010185
    56.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    #Fedora 42 just dropped a critical update for Keylime (7.14.1) patching CVE-2026-1709. Read more: 👉 https://tinyurl.com/mseytduy #Security https://t.co/AVb4Ca6c1d

    Post summary

    Fedora 42 released a critical update for Keylime version 7.14.1 that patches CVE-2026-1709, providing a vendor-supplied fix.

    0000039
    1.3K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Keylime updates for Archlinux and Fedora fix critical CVE-2026-1709 and CVE-2025-13609. Update to keylime 7.14.1 and keylime-agent-rust 0.2.9 to mitigate exposure. https://threatcluster.io/cluster/keylime-updates-address-critical-vulnerabilities-in-archlinu-96c6862f

    Post summary

    Keylime releases updates for Archlinux and Fedora to address critical CVE-2026-1709 and CVE-2025-13609, recommending users upgrade to keylime 7.14.1 and keylime-agent-rust 0.2.9.

    0000088
    89 followersView on X
  • VulnTracker@vuln_tracker
    General

    @the_yellow_fall You now can see the full detail about CVE-2026-1709 from https://vulntracker.io/cves/CVE-2026-1709

    Post summary

    The tweet simply points to a vulnerability detail page without providing specifics about the vulnerability or related exploitation.

    0000033
    333 followersView on X
  • cvereports@_cvereports
    General

    CVE-2026-1709: Keylime Pie with a Side of Open Access: The CVE-2026-1709 Deep Dive A critical authentication bypass in Keylime, a CNCF project designed for remote boot attestation using TPMs. ironically, the component responsible for verifying trust (... https://cvereports.com/reports/CVE-2026-1709

    Post summary

    The note briefly reports a critical authentication bypass in Keylime but offers no PoC, exploit code, active exploitation evidence, or remediation details.

    0000049
    27 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-1709 - Critical A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerabili... https://www.thehackerwire.com/vulnerability/CVE-2026-1709/ https://t.co/Z64YvDMo3y

    Post summary

    The post announces CVE‑2026‑1709, noting that Keylime’s registrar lacks client‑side TLS authentication, creating an authentication bypass. No PoC, exploitation, or patch details are mentioned.

    0000043
    113 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-1709: Keylime: keylime: authentication ... Critical TLS auth bypass in Keylime 7.12.0+ lets attackers perform admin operations without client certs—delete agents a... https://zerodaysignal.com/vulnerability/CVE-2026-1709 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    ZeroDaySignal announces a critical TLS authentication bypass (CVE‑2026‑1709) in Keylime 7.12.0+ that enables attackers to perform admin operations without client certificates.

    0000057
    132 followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
Appkeylimekeylime---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux9.0--
OSredhatenterprise_linux_eus10.0--
OSredhatenterprise_linux_for_arm_6410.0_aarch64--
OSredhatenterprise_linux_for_arm_649.0_aarch64--
OSredhatenterprise_linux_for_arm_64_eus10.0_aarch64--
OSredhatenterprise_linux_for_ibm_z_systems10.0_s390x--
OSredhatenterprise_linux_for_ibm_z_systems9.0_s390x--
OSredhatenterprise_linux_for_ibm_z_systems_eus10.0_s390x--
OSredhatenterprise_linux_for_power_little_endian10.0_ppc64le--
OSredhatenterprise_linux_for_power_little_endian9.0_ppc64le--
OSredhatenterprise_linux_for_power_little_endian_eus10.0_ppc64le--

Explore more