CVE-2026-1709: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-1709 is an authentication bypass vulnerability in the Keylime registrar component, described as "Keylime: Authentication bypass allows unauthorized administrative operations due to missing client-side TLS authentication." The flaw was introduced in Keylime version 7.12.0, where the registrar's TLS context is configured with ssl.CERT_OPTIONAL instead of ssl.CERT_REQUIRED, effectively disabling mutual TLS (mTLS) client certificate enforcement. All Keylime deployments running versions 7.12.0 through 7.13.0 (pip package) are affected, as well as Red Hat Enterprise Linux 9 and 10 systems shipping the vulnerable package. The vulnerability was disclosed on February 6, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 9.8 (Critical) per Feedly/Red Hat, and 9.4 (Critical) per the GitHub Advisory (Red Hat CVE, GitHub Advisory).

Technical details

The root cause is a single-line code defect in keylime/web/base/server.py, where self._ssl_ctx.verify_mode = CERT_OPTIONAL overrides the ssl.CERT_REQUIRED value previously set by web_util.init_mtls(), effectively nullifying client certificate validation for the registrar's HTTPS server (GitHub Advisory). This is classified under CWE-306 (Missing Authentication for Critical Function) and CWE-295 (Improper Certificate Validation). The attack vector is network-based with low complexity — any client with TCP access to the registrar's default HTTPS port (8891) can connect without presenting a client certificate and invoke protected REST API endpoints. No credentials, special tools, or prior authentication are required; a standard HTTP client such as curl is sufficient (Red Hat Bugzilla).

Impact

Successful exploitation allows unauthenticated remote attackers to perform administrative operations against the Keylime registrar, including enumerating all registered agents (GET /v2/agents/), retrieving agent details such as public TPM Endorsement Keys (EK), Attestation Keys (AK), certificates, and network locations (GET /v2/agents/{uuid}), and deleting agents from the registry (DELETE /v2/agents/{uuid}) (GitHub Advisory). While private TPM keys remain protected within TPM hardware and the HMAC secret is not exposed via the API, the ability to delete agents disrupts the remote attestation infrastructure, undermining the integrity and availability of systems relying on Keylime for boot-time and runtime integrity verification. This effectively breaks the zero-trust attestation chain for all managed nodes, with high confidentiality, integrity, and availability impact (Red Hat CVE).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the disclosure date (Feedly). The EPSS score is approximately 0.043% (8th percentile), indicating a currently low probability of exploitation in the next 30 days (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the trivial exploitation requirements — network access and a standard HTTP client — make it a high-priority patching target, particularly for environments where the registrar port is not network-isolated.

Exploitation steps

  1. Reconnaissance: Identify hosts running the Keylime registrar on versions 7.12.0–7.13.0 by scanning for open TCP port 8891 (default registrar HTTPS port) using tools like nmap or masscan.
  2. Verify vulnerability: Attempt a TLS connection to the registrar without presenting a client certificate (e.g., curl -k https://<registrar-host>:8891/v2/agents/) — a successful response (HTTP 200) confirms the mTLS bypass is active.
  3. Enumerate agents: Issue a GET request to list all registered agents: curl -k https://<registrar-host>:8891/v2/agents/ — this returns UUIDs and metadata for all enrolled agents.
  4. Retrieve TPM data: For each agent UUID, retrieve public TPM keys and network location: curl -k https://<registrar-host>:8891/v2/agents/<uuid> — this exposes EK, AK, certificates, and IP/port of the agent.
  5. Disrupt attestation: Delete one or more agents to break the attestation chain: curl -k -X DELETE https://<registrar-host>:8891/v2/agents/<uuid> — this removes the agent from the registry, causing attestation failures for the affected node (GitHub Advisory, Red Hat Bugzilla).

Indicators of compromise

  • Network: Unexpected HTTPS connections to TCP port 8891 (Keylime registrar) from hosts that are not the authorized verifier or tenant; connections lacking a client TLS certificate in server-side TLS handshake logs.
  • Logs: Keylime registrar access logs showing GET /v2/agents/, GET /v2/agents/<uuid>, or DELETE /v2/agents/<uuid> requests from unauthorized source IPs; absence of client certificate fields in TLS session logs for these requests.
  • Availability: Unexpected disappearance of agents from the Keylime registry; attestation failures for nodes that were previously successfully attested, potentially indicating agent deletion by an unauthorized party.
  • Process/Config: Keylime registrar process running version 7.12.0–7.13.0 (pip) or keylime-7.12.1-11.el9_7 / keylime-7.12.1-11.el10_1 packages prior to the .4 patch revision on RHEL (Red Hat Bugzilla, GitHub Advisory).

Mitigation and workarounds

Upgrade (recommended): Apply patched Keylime versions 7.12.2 or 7.13.1 (pip). For RHEL 9, apply RHSA-2026:2224 (package keylime-7.12.1-11.el9_7.4); for RHEL 10, apply RHSA-2026:2225 (package keylime-7.12.1-11.el10_1.4); for RHEL 10 EUS, apply RHSA-2026:2298. Fedora users should upgrade to keylime-7.14.1-1.fc42/fc43/fc44 (Red Hat RHSA-2026:2224, Red Hat RHSA-2026:2225). Workarounds (if immediate patching is not possible): (1) Use firewall rules to restrict access to port 8891 to only trusted verifier and tenant hosts (e.g., iptables -A INPUT -p tcp --dport 8891 -j DROP except from trusted IPs); (2) Deploy a reverse proxy (nginx or HAProxy) in front of the registrar configured with ssl_verify_client on to enforce client certificate authentication at the network boundary (GitHub Advisory).

Community reactions

Red Hat rated this vulnerability as Critical severity and issued three security advisories (RHSA-2026:2224, RHSA-2026:2225, RHSA-2026:2298) within three days of disclosure, reflecting the high priority assigned to the flaw (Red Hat RHSA-2026:2224). Security news outlet SecurityOnline.info covered the vulnerability with the headline "Trust Broken: Critical Keylime Flaw (CVSS 9.4) Disables mTLS Authentication," highlighting the implications for zero-trust infrastructure. The compliance community also noted the vulnerability's impact on TPM-based attestation pipelines, with compliancehub.wiki publishing analysis on its zero-trust implications. The CISA weekly vulnerability bulletin for the week of February 2, 2026 included this CVE, indicating broad awareness across the U.S. federal security community.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Fixed

RHEL 9

:appstream:keylime-0:7.12.1-11.el9_7.4.src

Fixed

RHEL 10

keylime-0:7.12.1-2.el10_0.5.src

Fixed

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management