Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-18796— QSPI flash encryption side-channel leakage

Quick assessment

Affected
Nordic Semiconductor ASA nRF5340
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

任何在 nRF5340 上使用外部 QSPI 闪存进行加密 XIP(就地执行)并依赖该加密来保障外部存储代码的机密性和/或完整性的应用程序。问题的根本原因并非某个特定版本的 nRF Connect SDK,而在于其“即时解密”机制本身存在缺陷。

CVSS 6.8 · Medium

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18796

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
QSPI flash encryption side-channel leakage
Source: CVE Program / CVE List V5
Vulnerability Description
Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally stored code. No specific nRF Connect SDK version is the root cause; the weakness is in the on-the-fly decryption scheme.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1342
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Nordic Semiconductor ASA nRF5340 All build codes -

II. Public POCs for CVE-2026-18796

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18796

登录查看更多情报信息。

Other References for CVE-2026-18796 (1)

Same Patch Batch · Nordic Semiconductor ASA · 2026-09-07 · 3 CVEs total

CVE-2026-14297 8.7 HIGH The Continuous Glucose Monitoring Service's Record Access Control Point (RACP) write handl
CVE-2026-14296 7.5 HIGH nRF54H20: MCUBoot can be tricked to executing unauthenticated code

IV. Related Vulnerabilities

V. Comments for CVE-2026-18796

No comments yet


Leave a comment