PT-2026-67570 · Unknown · Caliptra Core Rom

CVE-2026-11835

·

Published

2026-08-04

·

Updated

2026-08-04

CVSS v4.0

5.6

Medium

VectorAV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Caliptra Core ROM versions 2.1.0 through 2.1.1
Description A Time-of-check time-of-use (TOCTOU) issue combined with missing input validation in the UpdateResetFlow::run() function in subsystem mode allows a local attacker to bypass secure boot. By providing an AXI staging address that is not validated against the SS EXTERNAL STAGING AREA BASE ADDR, an attacker can modify firmware between the verification phase and its loading into the Instruction Cache and Tightly Coupled Memory (ICCM). This allows the compromise to remain hidden as attestation continues to report the digest of the originally verified image. Successful exploitation requires compromised MCU firmware with AXI manager access to unprotected SRAM reachable by Caliptra.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11835
GHSA-49MM-5GQ5-V97F

Affected Products

Caliptra Core Rom