PT-2026-99455 · Contrast · Contrast

·

CVE-2026-100835

·

Published

2026-09-27

·

Updated

2026-09-27

CVSS v4.0

9.1

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Contrast versions prior to 1.16.0
Description The software is susceptible to remote attestation relay attacks. The system accepted any Trusted Execution Environment (TEE) attestation report that verified correctly and contained the expected firmware patch levels and software measurements, without binding the attestation to specific, physically trusted hardware. An attacker capable of intercepting network traffic between the CLI and the Coordinator, or between the Coordinator and an attested component, could relay a report from a TEE machine under their physical control to impersonate a Contrast Coordinator or workload. This process defeats identity verification in the attested TLS (aTLS), a security mechanism used to ensure the identity of communicating parties in a TEE environment.
Recommendations Update to version 1.16.0 or later.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100835
GHSA-HJGC-JC5V-FW7H

Affected Products

Contrast