๐Ÿ” CVE Alert

CVE-2026-11835

UNKNOWN 0.0

Caliptra Update-Reset Secure-Boot Bypass via Attacker-Chosen AXI Staging Address (TOCTOU)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mode allows a compromised local attacker to silently bypass secure boot by supplying an AXI staging address that is not validated against the strap-configured SS_EXTERNAL_STAGING_AREA_BASE_ADDR, enabling firmware to be modified between verification and loading into ICCM. Attestation continues to report the originally verified image digest, masking the compromise. Exploitation requires a compromised MCU firmware with AXI manager access to unprotected SRAM reachable by Caliptra. This issue affects Core ROM: 2.1.0 through 2.1.1.

CWE CWE-367 CWE-20
Vendor caliptra
Product core rom
Published Aug 4, 2026
Last Updated Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for caliptra core rom

Be the first to know when new unknown vulnerabilities affecting caliptra core rom are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Caliptra / Core ROM
2.1.0 โ‰ค 2.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/chipsalliance/caliptra-sw/security/advisories/GHSA-49mm-5gq5-v97f