CVE-2026-100835
Received Received - Intake

Remote Attestation Relay Attack in Contrast

Vulnerability report for CVE-2026-100835, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: VulnCheck

Description

Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and software measurements, regardless of which machine produced it, so attestation was not bound to specific, physically trusted hardware. An attacker who can both intercept network traffic between the CLI and the Coordinator (or between the Coordinator and an attested component) and forge reports or extract secrets from any single TEE machine under their physical control can relay such a report to impersonate a Contrast Coordinator or a Contrast workload, defeating identity verification in Contrast's attested TLS (aTLS).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-27
AI Q&A
2026-09-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
contrast contrast to 1.16.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Contrast before version 1.16.0 is vulnerable to a remote attestation relay attack. The system accepted any valid Trusted Execution Environment (TEE) attestation report, even if it came from an untrusted machine. Attackers can intercept network traffic between components and relay forged or extracted reports from a compromised TEE to impersonate a Contrast Coordinator or workload, bypassing identity verification in attested TLS (aTLS).

Detection Guidance

Detecting this vulnerability requires checking if your Contrast version is below 1.16.0. Use commands like 'contrast version' or inspect configuration files for version details. Monitor network traffic between CLI and Coordinator or between Coordinator and attested components for unusual relayed attestation reports.

Impact Analysis

An attacker could impersonate your Contrast system or workloads, gaining unauthorized access to sensitive data or operations. This could lead to data breaches, service disruption, or unauthorized system control. The attack requires intercepting network traffic and controlling a single TEE machine, but successful exploitation defeats hardware-based security measures.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's integrity and confidentiality requirements or HIPAA's safeguards for protected health information. Compliance may be compromised due to potential data breaches or loss of hardware-based trust in systems handling regulated data.

Mitigation Strategies

Upgrade Contrast to version 1.16.0 or later immediately. If upgrading is not possible, restrict validation to trusted hardware by adding AllowedChipIDs for SEV-SNP or AllowedPIIDs for TDX in the manifest. Ensure network traffic between components is encrypted and monitored for anomalies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100835. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart