CVE-2026-30836Disclosure(smallstep / step-ca)

LOWCVSS 10.0 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch smallstep step-ca systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • step-ca

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 7 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-19); latest day: 2
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
step-ca

1 version affected across 1 product

Deep dive

Activity timeline8 mentions / 4d
01223Mentions · 2026-03-19: 3Mentions · 2026-03-20: 2Mentions · 2026-03-21: 1Mentions · 2026-03-23: 2Patch / Workaround · 2026-03-19: 1Patch / Workaround · 2026-03-21: 1Technical Details · 2026-03-19: 3Technical Details · 2026-03-20: 2Technical Details · 2026-03-21: 1Technical Details · 2026-03-23: 103-1903-2003-2103-23
Signal classification2 categories
Disclosure
787.5%
Patch
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-193
Disclosure2Patch1
2026-03-202
Disclosure2
2026-03-211
Disclosure1
2026-03-232
Disclosure2
Full discourse8 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    `step-ca` is vulnerable to unauthenticated certificate issuance via SCEP UpdateReq (MessageType=18), enabling unauthorized certificate acquisition. Monitor for a fix for CVE-2026-30836. #stepca #PKI #infosec https://www.pulsepatch.io/posts/cve-2026-30836-step-ca-unauthenticated-certificate-issuance

    Post summary

    The post announces a new CVE-2026-30836 vulnerability in step‑ca that permits unauthenticated certificate issuance via SCEP UpdateReq, urging users to seek a forthcoming fix.

    0001027
    2 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-30836 Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthentic… https://www.cve.org/CVERecord?id=CVE-2026-30836 ----- Traducción: CVE-2026-30836 Ste… http://infoflow.cloud`

    Post summary

    The post announces a new CVE (CVE-2026-30836) in Step CA, noting that older versions lack authentication safeguards for certificates.

    0000013
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30836 Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthentic… https://www.cve.org/CVERecord?id=CVE-2026-30836

    Post summary

    The text announces CVE‑2026‑30836, noting that Step CA versions 0.30.0‑rc6 and earlier lack authentication safeguards, but provides no further technical or mitigation details.

    00000117
    56.8K followersView on X
  • Vulert@vulert_official
    Disclosure

    🚨 Critical Step CA Flaw: CVE-2026-30836 A serious unauthenticated certificate issuance vulnerability in Step CA could let attackers obtain unauthorized certificates and undermine secure communications. 🔍 More details: https://vulert.com/vuln-db/CVE-2026-30836 #CyberSecurity #StepCA #CVE202630836 https://t.co/DEHcAONxQX

    Post summary

    The tweet announces CVE-2026-30836, describing it as a serious unauthenticated certificate issuance flaw in Step CA, without providing PoC, exploit code, or patch details.

    0000033
    123 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30836 Unauthenticated Certificate Issuance Vulnerability in Step CA Before 0.30.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30836

    Post summary

    A new unauthenticated certificate issuance vulnerability (CVE-2026-30836) in Step CA versions prior to 0.30.0 is disclosed, with no exploitation or mitigation details provided.

    0000040
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-30836 - Critical Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issu... https://www.thehackerwire.com/vulnerability/CVE-2026-30836/ https://t.co/mXtSBAOghy

    Post summary

    The post announces a Critical CVE‑2026‑30836 affecting Step CA, noting that versions up to 0.30.0‑rc6 permit unauthenticated certificate issuance, without detailing exploits, patches, or active attacks.

    0000053
    137 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-30836: CRITICAL] Online certificate authority Step CA was vulnerable to unauthenticated certificate issuance in versions 0.30.0-rc6 and earlier, fixed in version 0.30.0 for enhanced cybersecurity.#cve,CVE-2026-30836,#cybersecurity https://cvefind.com/CVE-2026-30836

    Post summary

    The Step CA vulnerability (CVE‑2026‑30836) permits unauthenticated certificate issuance, was disclosed as critical, and has been fixed in version 0.30.0.

    0000053
    603 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-30836: Step CA: Unaut... SCEP UpdateReq bypasses all auth checks in Step CA—attackers can mint valid certs for any domain without credentials. #PKI #SCEP #StepCA. https://zerodaysignal.com/vulnerability/CVE-2026-30836 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑30836, a Step CA issue where the SCEP UpdateReq endpoint bypasses authentication, allowing attackers to issue valid certificates for any domain without credentials.

    0000058
    154 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appsmallstepstep-ca-go-
Appsmallstepstep-ca0.30.0go-
Appsmallstepstep-ca0.30.0go-
Appsmallstepstep-ca0.30.0go-
Appsmallstepstep-ca0.30.0go-
Appsmallstepstep-ca0.30.0go-
Appsmallstepstep-ca0.30.0go-

Explore more