One HTTP Request, Full Trust Poisoning: ADSys’s Certificate Enrollment Flaw
The Vulnerability in the Enrollment Pathway The security of an enterprise trust store is fundamentally limited by the integrity of the enrollment mechanism that populates it. When that enrollment pathway relies on plaintext communication, the trust infrastructure itself becomes a viable attack surface. This reality is underscored by CVE-2026-12249 vulnerability, a critical flaw in Canonical…