PT-2026-79500 · Unknown · Fort Validator

CVE-2026-53499

·

Published

2026-08-21

·

Updated

2026-08-25

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions FORT Validator versions prior to 1.6.8
Description FORT Validator, a Resource Public Key Infrastructure (RPKI) relying-party validator, contains an origin-validation error in its RRDP processing. A delegated CA under the same Trust Anchor Locator (TAL) can reference a victim CA’s public RRDP notification and snapshot URLs. This causes the URL-based download cache to report success after deleting the victim’s local snapshot. Consequently, routine victim publications may silently remove Validated ROE (VRPs) and other signed objects from the output, which could lead to route hijacking or loss of reachability.
Recommendations Update to version 1.6.8. As a temporary workaround, disable HTTP/RRDP by setting the --http.enabled=false variable while keeping rsync enabled.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53499
GHSA-QFM3-577X-RH54

Affected Products

Fort Validator