CVE-CVE-2026-100835
Severity
HIGH
CVSS Score
7.4
Description
Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and software measurements, regardless of which machine produced it, so attestation was not bound to specific, physically trusted hardware. An attacker who can both intercept network traffic between the CLI and the Coordinator (or between the Coordinator and an attested component) and forge reports or extra...
PoCs for CVE-CVE-2026-100835
CVE-2026-100835
General
Python
0
murrez
2026-09-27