CVE-2026-100835 Details
Description
Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and software measurements, regardless of which machine produced it, so attestation was not bound to specific, physically trusted hardware. An attacker who can both intercept network traffic between the CLI and the Coordinator (or between the Coordinator and an attested component) and forge reports or extract secrets from any single TEE machine under their physical control can relay such a report to impersonate a Contrast Coordinator or a Contrast workload, defeating identity verification in Contrast's attested TLS (aTLS).
A remote attestation relay vulnerability has been identified in Contrast versions prior to 1.16.0. This issue arises because Contrast accepted any TEE attestation report that verified correctly and included the expected firmware patch levels and software measurements, without binding the attestation to specific, physically trusted hardware. As a result, an attacker who can intercept network traffic between the CLI and the Coordinator (or between the Coordinator and an attested component) and who can forge reports or extract secrets from a TEE machine under their physical control can relay such a report to impersonate a Contrast Coordinator or a Contrast workload. This exploitation defeats identity verification in Contrast's attested TLS (aTLS).
Users can update to Contrast version 1.16.0 or later, where this vulnerability has been addressed. In version 1.16.0, two new manifest fields were introduced: 'AllowedChipIDs' for SEV-SNP and 'AllowedPIIDs' for TDX. Workload owners must populate these fields with the IDs of hardware known to be protected from physical attacks.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Edgelesssys Contrast | < 1.16.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 27, 2026 | New CVE Received | [email protected] |
Volerion