PT-2026-99447 · Contrast · Contrast

·

CVE-2025-71426

·

Published

2025-02-05

·

Updated

2026-09-27

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Contrast versions prior to 1.4.1
Description A recovering Coordinator fails to verify the seed provided by the recovering party. This allows an attacker to establish a rogue Coordinator with a validated manifest but an attacker-controlled secret seed. If network traffic is redirected to this rogue Coordinator, an attacker can impersonate a workload owner if the owner sets a new manifest without comparing the returned root CA certificate to the existing one or verifies the Coordinator without a trusted reference. Consequently, the attacker can issue certificates chaining to the rogue Coordinator's root CA to recover workload secrets for workloads deployed after the attack.
Recommendations Update to version 1.4.1 or later.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71426
GHSA-VQV5-385R-2HF8
GO-2025-3455

Affected Products

Contrast