PT-2026-92026 · Undefined · Undefined
CVE-2026-25825
·
Published
2026-09-15
·
Updated
2026-09-22
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Keyfactor SignServer versions prior to 7.6.0
Description
An issue exists where the output file used by the
SignerStatusReportWorker for logging reports can be configured to any path, including those of existing files. This allows a user with administrative privileges to write files to arbitrary directories within the server filesystem and potentially overwrite files accessible by the local JBoss user.Recommendations
Update Keyfactor SignServer to version 7.6.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined