CVE-2026-100835

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and software measurements, regardless of which machine produced it, so attestation was not bound to specific, physically trusted hardware. An attacker who can both intercept network traffic between the CLI and the Coordinator (or between the Coordinator and an attested component) and forge reports or extract secrets from any single TEE machine under their physical control can relay such a report to impersonate a Contrast Coordinator or a Contrast workload, defeating identity verification in Contrast's attested TLS (aTLS).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-27: 109-27
Referenced assets1 URL
By indicator
Full discourse1 post
  • mürrez@murrezsec

    New PoC live — CVE-2026-100835 🔍 Edgeless Contrast (<1.16.0): remote attestation relay breaks aTLS identity (CWE-295). Manifest audit, version/K8s checks, Coordinator probe — no MITM in repo. 📖PoC: https://pocbit.org/pocs/cve-2026-100835 #CVE #CyberSecurity #PoC #InfoSec

    1002023
    607 followersView on X

Explore more