CVE-2025-26787 Details
Description
An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CLI command used to configure Certificate access to the initial startup of the container sets a property of "allowany" to allow any user with a valid and trusted client auth certificate to connect. Admins can then set more restricted access to specific certificates. A logic error caused this admin CLI command to be run on each restart of the container instead of only the first startup as intended resetting the configuration to "allowany".
A vulnerability exists in Keyfactor SignServer container deployments prior to version 7.2, related to the Admin CLI command that configures certificate access. This command inadvertently resets the access configuration to 'allowany' on each container restart, instead of only during the initial startup. As a result, any user with a valid and trusted client authentication certificate can gain access to the AdminWeb as an administrator, undermining more restrictive access controls that may have been established.
Users of Keyfactor SignServer Container should update to version 7.2 and verify that the 'Allow Only Listed' configuration is set as intended. After updating, confirm the version in the AdminWeb and check the certificate access settings.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-642 | External Control of Critical State Data | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| keyfactor signserver | < 7.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 5, 2026 | Initial Analysis | [email protected] |
| Dec 22, 2025 | New CVE Received | [email protected] |
| Dec 22, 2025 | CVE Modified | CISA-ADP |