PT-2026-92027 · Undefined · Undefined
CVE-2026-25826
·
Published
2026-09-15
·
Updated
2026-09-22
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Keyfactor SignServer versions prior to 7.6.0
Description
An issue exists where the
ATTRIBUTESFILE attribute in PKCS11CryptoToken can be configured to point to a readable file that is not recognized as a valid attribute file. When this occurs, the system generates an error that includes the full content of the file within the application server log. An attacker with SignServer administrative privileges and access to the server logs, such as through remote syslog shipping, can exploit this to read files accessible by the local JBoss user.Recommendations
Update Keyfactor SignServer to version 7.6.0 or later.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined