CVE-2026-7328
Unverified AXI Address in Subsystem Mode Commands Enables Denial of Service
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged local attacker to cause a denial of service via mailbox commands containing unverified AXI addresses. The security impact beyond availability is integration-specific. This issue affects Core Runtime Firmware: 2.1.0.
| CWE | CWE-862 |
| Vendor | caliptra |
| Product | core runtime firmware |
| Published | Jul 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for caliptra core runtime firmware
Be the first to know when new unknown vulnerabilities affecting caliptra core runtime firmware are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Caliptra / Core Runtime Firmware
2.1.0