VAITP Dataset

← Back to the dataset

CVE-2026-12249

ADSys uses HTTP for cert enrollment, allowing MITM trust store poisoning.

  • CVSS 9.0
  • CWE-348
  • Cryptographic
  • Remote

An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Samba client script (internal/policies/certificate/python/vendor_samba/gp/gp_cert_auto_enroll_ext.py), ADSys utilizes a plaintext HTTP connection (http://) instead of a secure HTTPS connection (https://) to request the CA certificate from the Active Directory Certificate Services server (GetCACert). An unauthenticated network attacker positioned between the managed Ubuntu host and the configured AD CS CA hostname can conduct a Man-in-the-Middle (MITM) attack. By intercepting the plaintext HTTP request, the attacker can supply an arbitrary, attacker-controlled Root CA certificate. Because the system automatically accepts this certificate and registers it into the local system trust store via update-ca-certificates, this results in system-wide trust store poisoning. Consequently, TLS clients utilizing the operating system trust store on the affected machine will accept rogue certificates for arbitrary domains, enabling persistent decryption and interception of subsequent TLS connections. This issue is resolved in version v0.16.3.

CVSS base score
9.0
Published
2026-06-22
OWASP
A08 Software and Data Integrity Failures
Orthogonal defect classification
Interface
Code defect classification
Incorrect Functionality
Category
Cryptographic
Subcategory
Unencrypted communication
Accessibility scope
Remote
Impact
Information Disclosure
Affected component
Canonical AD
Fixed by upgrading
Yes

Solution

Upgrade Canonical ADSys to version v0.16.3 or later.

Vulnerable code sample

import requests
import subprocess
import os

def fetch_and_install_ca_cert_vulnerable(ad_cs_hostname: str):
    """
    This is a representative code example of the vulnerability described
    in CVE-2026-12249, as found in ADSys versions up to v0.16.2.

    The function fetches a CA certificate from an Active Directory
    Certificate Services (AD CS) server and installs it into the
    system-wide trust store.
    """

    # VULNERABILITY: The URL is constructed using plaintext 'http://'.
    # A Man-in-the-Middle attacker can intercept this request.
    url = f"http://{ad_cs_hostname}/certsrv/certnew.cer?ReqID=CACert&Enc=b64"

    cert_install_path = "/usr/local/share/ca-certificates/"
    cert_file_path = os.path.join(cert_install_path, f"{ad_cs_hostname}.crt")

    try:
        # The request to fetch the CA certificate is made over an unencrypted channel.
        # An attacker can intercept this and substitute their own malicious CA certificate.
        response = requests.get(url, timeout=10)
        response.raise_for_status()

        # The system takes the received certificate data, which may be attacker-controlled.
        ca_cert_data = response.content

        # The potentially malicious certificate is written to a file in a location
        # read by the system's trust store update mechanism.
        # This part of the code requires root privileges to execute successfully.
        if not os.path.exists(cert_install_path):
            os.makedirs(cert_install_path, exist_ok=True)
        
        with open(cert_file_path, "wb") as f:
            f.write(ca_cert_data)

        # The system blindly trusts the downloaded certificate and runs
        # 'update-ca-certificates'. This adds the attacker's certificate to the
        # system-wide trust store, resulting in trust store poisoning.
        subprocess.run(["update-ca-certificates"], check=True, capture_output=True)

    except requests.exceptions.RequestException as e:
        # In a real-world scenario, errors would be logged.
        # The vulnerability exists in the successful execution path.
        pass
    except (IOError, subprocess.CalledProcessError) as e:
        # These errors would occur due to permissions or other system issues.
        pass

Patched code sample

import urllib.request
import ssl
import logging

def fetch_ca_certificate(adcs_server_hostname: str, ca_name: str):
    """
    Securely fetches the CA certificate from the AD CS server, demonstrating
    the fix for CVE-2026-12249.

    The vulnerability was that a plaintext 'http://' URL was used, allowing
    a Man-in-the-Middle attacker to intercept the request and provide a
    malicious root CA certificate, poisoning the system's trust store.

    The fix is to enforce the use of 'https://' for this request, ensuring
    the connection is encrypted and the server's identity is verified.
    """
    
    # The vulnerable code used an HTTP URL like this:
    # vulnerable_url = f"http://{adcs_server_hostname}/certsrv/certnew.cer?ReqID=CACert&Renewal=0&Enc=b64&CaName={ca_name}"

    # The fix is to construct the URL using HTTPS to ensure a secure, encrypted connection.
    secure_url = f"https://{adcs_server_hostname}/certsrv/certnew.cer?ReqID=CACert&Renewal=0&Enc=b64&CaName={ca_name}"

    logging.info(f"Securely fetching CA certificate from: {secure_url}")

    try:
        # By using an https:// URL, urllib performs TLS encryption.
        # The default SSL context verifies the server's certificate against the
        # local trust store, preventing MITM attacks.
        request = urllib.request.Request(secure_url)
        with urllib.request.urlopen(request, context=ssl.create_default_context()) as response:
            if response.status == 200:
                cert_data = response.read()
                logging.info("Successfully fetched CA certificate over HTTPS.")
                # In the real application, this data is then used to update
                # the system's CA certificates.
                return cert_data
            else:
                logging.error(f"Failed to fetch certificate. Server responded with status: {response.status}")
                return None
    except Exception as e:
        logging.error(f"An error occurred while fetching the certificate: {e}")
        return None

Payload

-----BEGIN CERTIFICATE-----
MIIDdzCCAl+gAwIBAgIUQj5c42S5aL671arsy3ytr2kflvwwDQYJKoZIhvcNAQEL
BQAwYDELMAkGA1UEBhMCWFgxEDAOBgNVBAgMB05ldHdvcmsxFDASBgNVBAoMC01J
VE0gSW5jLCAuMRwwGgYDVQQDDBNBdHRhY2tlciBSb290IENBIDEwHhcNMjQwNTAx
MTYzODQ1WhcNMzQwNDI5MTYzODQ1WjBgMQswCQYDVQQGEwJYWDEQMA4GA1UECAwH
TmV0d29yazEUMBIGA1UECgwLTUlUTSBMbmMsIC4xHDAaBgNVBAMME0F0dGFja2Vy
IFJvb3QgQ0EgMTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMN+8b9J
q6L2aV5x3C8aa6EVO1N9I4hky4Pgi7T3nIXjDgb4gC2PqWW8E3MAG81pg3UIIcLO
kL3wVw4a7d3h/2J6QyL3sV6v5n8h7e6s9k4p3g2f1x8y1z7r5c6n3k1m8d5c7f9q
2b4l3j9i8k6m3f0h9g7c5e4f3b2a1c9h8g6k5j4l3h2g1f9i8k6m3f0h9g7c5e4f
3b2a1c9h8g6k5j4l3h2g1f9i8k6m3f0h9g7c5e4f3b2a1c9h8g6k5j4l3h2g1f9i
8k6m3f0h9g7c5e4f3b2a1c9h8g6k5j4l3h2g1f9i8k6m3f0h9g7c5e4f3b2a1c9h
8g6k5j4l3h2g1f9i8k6m3f0h9g7c5e4f3b2a1c9h8g6k5j4l3h2g1f9i8k6m3f0h
9g7c5e4f3b2a1c9h8g6k5j4l3h2g1f9i8k6m3f0h9g7c5e4f3b2a1wIDAQABo1Mw
UTAdBgNVHQ4EFgQU/3j/7k/l/1k/j/5k/l/3j/7k/l8wHwYDVR0jBBgwFoAU/3j/
7k/l/1k/j/5k/l/3j/7k/l8wDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsF
AAOCAQEAgI7B/8c/9i/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/
8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8
f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h
/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/
8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8
f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h
/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/
8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8
f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g/8c/8f/9h/8g==
-----END CERTIFICATE-----

Cite this entry

@misc{vaitp:cve202612249,
  title        = {{ADSys uses HTTP for cert enrollment, allowing MITM trust store poisoning.}},
  author       = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
  year         = {2026},
  note         = {VAITP Python Vulnerability Dataset, entry CVE-2026-12249},
  howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-12249/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::