
CVE-2026-40097 Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to before 0.30.0-rc3, an attacker can trigger an index… https://www.cve.org/CVERecord?id=CVE-2026-40097
Post summary
The post notes a CVE for Step CA where versions 0.24.0 to before 0.30.0-rc3 may allow an attacker to trigger an index, but it does not provide PoC, exploitation code, patch details, or evidence of active exploitation.


