Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100835— Contrast before 1.16.0 Remote Attestation Relay Attack

Quick assessment

Affected
edgelesssys contrast
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Contrast 版本低于 1.16.0 的系统容易受到远程认证中继攻击。Contrast 接受任何经过正确验证且包含预期固件补丁级别和软件测量值的 TEE(可信执行环境)认证报告,而不论该报告由哪台机器生成,因此认证过程未绑定到特定的、物理上可信的硬件。如果攻击者能够拦截 CLI(命令行接口)与协调器(Coordinator)之间(或协调器与已认证的组件之间)的网络流量,并且能够伪造报告或从其物理控制的任意一台 TEE 机器中提取密钥,那么攻击者就可以将此类报告中继转发,从而冒充 Contrast 协调器或 Co

CVSS 7.4 · High EPSS 0.22% · P11
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100835

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Contrast before 1.16.0 Remote Attestation Relay Attack
Source: CVE Program / CVE List V5
Vulnerability Description
Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and software measurements, regardless of which machine produced it, so attestation was not bound to specific, physically trusted hardware. An attacker who can both intercept network traffic between the CLI and the Coordinator (or between the Coordinator and an attested component) and forge reports or extract secrets from any single TEE machine under their physical control can relay such a report to impersonate a Contrast Coordinator or a Contrast workload, defeating identity verification in Contrast's attested TLS (aTLS).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
edgelesssys contrast 0 ~ 1.16.0 -

II. Public POCs for CVE-2026-100835

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100835

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100835 (1)

Other References for CVE-2026-100835 (1)

Same Patch Batch · edgelesssys · 2026-09-27 · 11 CVEs total

CVE-2026-100839 8.4 HIGH Contrast before 1.18.0 AML Injection Remote Code Execution
CVE-2026-100833 8.2 HIGH Contrast before 1.23.1 Image Substitution via Policy Generation
CVE-2026-100838 8.1 HIGH Contrast before 1.19.1 CopyFile Policy Symlink Subversion
CVE-2025-71425 7.3 HIGH Contrast before 1.8.1 Information Disclosure via Logging
CVE-2025-71423 7.3 HIGH Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure
CVE-2025-71426 7.1 HIGH Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery
CVE-2025-71422 5.7 MEDIUM Contrast before 1.12.1 Insecure LUKS2 Persistent Storage
CVE-2026-100836 4.3 MEDIUM Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextContainer
CVE-2026-100837 3.7 LOW Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching
CVE-2025-71424 3.5 LOW Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount

IV. Related Vulnerabilities

V. Comments for CVE-2026-100835

No comments yet


Leave a comment