Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.

Project Subscriptions

No data.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-q4r8-xm5f-56gw step-ca has Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 19 Mar 2026 20:45:00 +0000

Type Values Removed Values Added
Description Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.
Title Step CA: Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)
Weaknesses CWE-287
CWE-295
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-19T20:37:05.757Z

Reserved: 2026-03-05T21:06:44.606Z

Link: CVE-2026-30836

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-19T21:17:09.783

Modified: 2026-03-19T21:17:09.783

Link: CVE-2026-30836

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses