Loading
Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.
Use CWE-287, Smallstep vendor hub and Step-Ca product page to widen CVE-2026-30836 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-40097 for nearby disclosures in the same product family.