Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard aga...
Description
Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.
AI Analyst Comment
Remediation
Update Step Multiple Products to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Smallstep
PRODUCT: Step CA
AFFECTED_VERSIONS: < 0.30.0
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
Smallstep Step CA versions below 0.30.0 are vulnerable to an improper authentication flaw in the SCEP UpdateReq function, allowing unauthenticated attackers to issue certificates.
Executive Summary:
A critical authentication bypass in Smallstep Step CA allows unauthenticated attackers to issue unauthorized digital certificates, potentially undermining the entire PKI infrastructure.
Vulnerability Details
CVE-ID: CVE-2026-30836
Affected Software: Smallstep Step CA
Affected Versions: < 0.30.0
Vulnerability: This vulnerability is caused by a failure to properly authenticate requests during the SCEP UpdateReq process. An unauthenticated attacker can exploit this to perform unauthorized certificate issuance, which violates the fundamental security assumptions of the certificate authority.
Business Impact
The ability for an unauthenticated actor to issue certificates poses a catastrophic risk to the organization's PKI infrastructure. With a CVSS score of 10.0, this vulnerability could allow attackers to perform man-in-the-middle attacks, impersonate legitimate services, or decrypt secure communications, leading to total loss of trust in the system.
Remediation Plan
Immediate Action: Update Smallstep Step CA to version 0.30.0 or later to ensure proper authentication is enforced for all certificate requests.
Proactive Monitoring: Audit existing certificate issuance logs for any unauthorized or unexpected certificate requests that occurred prior to the update.
Compensating Controls: Restrict access to the SCEP endpoint at the network level using firewalls or mutual TLS (mTLS) to ensure only authorized entities can interact with the service.
Exploitation Status
Public Exploit Available: False
Analyst Notes: As of Mar 19, 2026, there is no public information indicating active exploitation. However, the criticality of this vulnerability (CVSS 10) indicates that it should be mitigated immediately to prevent potential large-scale security breaches.
Analyst Recommendation
This vulnerability represents the highest level of risk to security infrastructure. Organizations must upgrade to version 0.30.0 immediately and conduct a thorough audit of their certificate store to ensure no unauthorized certificates have been issued.