PT-2026-79500 · Unknown · Fort Validator
CVE-2026-53499
·
Published
2026-08-21
·
Updated
2026-08-25
CVSS v4.0
7.2
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
FORT Validator versions prior to 1.6.8
Description
FORT Validator, a Resource Public Key Infrastructure (RPKI) relying-party validator, contains an origin-validation error in its RRDP processing. A delegated CA under the same Trust Anchor Locator (TAL) can reference a victim CA’s public RRDP notification and snapshot URLs. This causes the URL-based download cache to report success after deleting the victim’s local snapshot. Consequently, routine victim publications may silently remove Validated ROE (VRPs) and other signed objects from the output, which could lead to route hijacking or loss of reachability.
Recommendations
Update to version 1.6.8.
As a temporary workaround, disable HTTP/RRDP by setting the
--http.enabled=false variable while keeping rsync enabled.Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fort Validator