CVE-2026-5818 Details
Description
Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) allows bypass of Caliptra Core's verification of the MCU FW during a hitless update. This issue affects Core Runtime Firmware: from 2.0.0 through 2.0.1, 2.1.0.
A vulnerability in Caliptra Core Runtime Firmware versions 2.0.0, 2.0.1, and 2.1.0 allows for an authentication bypass during firmware updates. The issue arises in the ActivateFirmwareCmd::activate_fw module, where the firmware authorization check is improperly handled. This flaw can lead to a time-of-check time-of-use vulnerability, enabling unauthorized firmware to be loaded and executed without detection or reporting by Caliptra.
Users can upgrade to Caliptra Core Runtime Firmware versions 2.0.2 or 2.1.1 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/chipsalliance/caliptra-sw/security/advisories/GHSA-456r-gcjr-6rxq | Caliptra |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-253 | Incorrect Check of Function Return Value | Caliptra |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | Caliptra |