CVE-2026-42769 | OpenSSL up to 3.4.5/3.5.6/3.6.2/4.0.0 OSSL_CMP_get1_rootCaKeyUpdate certificate validation
A vulnerability classified as problematic has been found in OpenSSL up to 3.4.5/3.5.6/3.6.2/4.0.0. This issue affects the function OSSL_CMP_get1_rootCaKeyUpdate. This manipulation causes improper certificate validation.
This vulnerability is handled as CVE-2026-42769. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.