Contrast before 1.16.0 is susceptible to remote attestation relay attacks. (CVE-2026-100835)
Contrast versions before 1.16.0 are vulnerable to remote attestation relay attacks. The product accepted any valid TEE attestation report with expected firmware and software measurements regardless of the originating hardware, allowing attackers to impersonate trusted components by relaying or forging reports. This flaw undermines identity verification in Contrast's attested TLS (aTLS) mechanism.
AI Analysis
Technical Summary
Contrast before version 1.16.0 does not bind TEE attestation reports to specific, physically trusted hardware. It accepts any attestation report that verifies correctly and contains expected firmware patch levels and software measurements, regardless of which machine produced it. An attacker capable of intercepting network traffic between the CLI and Coordinator or between the Coordinator and an attested component, and who can forge reports or extract secrets from any single TEE machine under their control, can relay such reports to impersonate a Contrast Coordinator or workload. This defeats the identity verification process in Contrast's attested TLS (aTLS).
Potential Impact
An attacker who can intercept relevant network traffic and control at least one TEE machine can impersonate trusted components within Contrast's attested TLS system, potentially compromising confidentiality and integrity of communications. The vulnerability affects identity verification, leading to high confidentiality and integrity impact, but does not affect availability.
Mitigation Recommendations
No patch or remediation information is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Contrast before 1.16.0 is susceptible to remote attestation relay attacks. (CVE-2026-100835)
Description
Contrast versions before 1.16.0 are vulnerable to remote attestation relay attacks. The product accepted any valid TEE attestation report with expected firmware and software measurements regardless of the originating hardware, allowing attackers to impersonate trusted components by relaying or forging reports. This flaw undermines identity verification in Contrast's attested TLS (aTLS) mechanism.
CVSS v3.1
Score 7.4high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Contrast before version 1.16.0 does not bind TEE attestation reports to specific, physically trusted hardware. It accepts any attestation report that verifies correctly and contains expected firmware patch levels and software measurements, regardless of which machine produced it. An attacker capable of intercepting network traffic between the CLI and Coordinator or between the Coordinator and an attested component, and who can forge reports or extract secrets from any single TEE machine under their control, can relay such reports to impersonate a Contrast Coordinator or workload. This defeats the identity verification process in Contrast's attested TLS (aTLS).
Potential Impact
An attacker who can intercept relevant network traffic and control at least one TEE machine can impersonate trusted components within Contrast's attested TLS system, potentially compromising confidentiality and integrity of communications. The vulnerability affects identity verification, leading to high confidentiality and integrity impact, but does not affect availability.
Mitigation Recommendations
No patch or remediation information is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-jw33-f4wc-8736
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-100835"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6ab89bc2f7a7c54106941ecd
Added to database: 09/27/2026, 04:29:54 UTC
Last enriched: 09/27/2026, 04:36:35 UTC
Last updated: 09/27/2026, 06:47:55 UTC
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.