← Back to browse · API

CVE-2026-30836

Severity
CRITICAL
CVSS
10.0
EPSS
0.00296
Risk score
40.1
CISA KEV
No
PoC
Yes
Published
2026-03-19
Modified
2026-03-25
First seen
2026-08-07
Aliases
EUVD-2026-13200, GHSA-Q4R8-XM5F-56GW
Products
linux, smallstep:certificates < 0.30.0, suse
Sources
packetstorm e760ebd193aaec6c0d4acb9c|CVE-2026-30836
euvd EUVD-2026-13200

Description

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.

References