Contrast · Contrast · CVE-2025-71426
**Name of the Vulnerable Software and Affected Versions**
Contrast versions prior to 1.4.1
**Description**
A recovering Coordinator fails to verify the seed provided by the recovering party. This allows an attacker to establish a rogue Coordinator with a validated manifest but an attacker-controlled secret seed. If network traffic is redirected to this rogue Coordinator, an attacker can impersonate a workload owner if the owner sets a new manifest without comparing the returned root CA certificate to the existing one or verifies the Coordinator without a trusted reference. Consequently, the attacker can issue certificates chaining to the rogue Coordinator's root CA to recover workload secrets for workloads deployed after the attack.
**Recommendations**
Update to version 1.4.1 or later.