CVE-2026-6726
Received Received - Intake

Information Leakage in TCG TPM 2.0 Reference Code

Vulnerability report for CVE-2026-6726, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: CERT/CC

Description

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a local attacker with elevated privileges to steal a credential from a TPM-aware Certificate Authority (CA) for a fake TPM key. The attacker can then use this credential to create false attestations for other TPM 2.0 operations, such as Attestation Keys, DevID Keys, or TLS authentication keys.

Impact Analysis

If exploited, this vulnerability could let attackers impersonate trusted TPM keys, leading to unauthorized access to systems or data. It may also enable false authentication, allowing attackers to bypass security controls or perform actions as a legitimate TPM device.

Mitigation Strategies

Apply patches or updates from the TCG TPM 2.0 reference code vendor if available. Monitor for suspicious TPM key usage or attestation requests. Review and restrict local elevated privileges that could exploit this issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-6726. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart