TLS session vulnerability in Enclave OS Mini by PrivaSys
CVE-2026-108265

9.1CRITICAL

Key Information:

Vendor

Privasys

Vendor
CVE Published:
9 October 2026

What is CVE-2026-108265?

Prior to the release of wasm-v0.40.0, Enclave OS Mini contained a vulnerability related to TLS session management. The SGX runtime failed to properly bind attestation data to the active TLS session, allowing an attacker to exploit this flaw. If an attacker were to acquire an enclave's TLS private key, they could relay a legitimate attestation quote to establish an unauthorized connection. This could mislead a relying party, resulting in acceptance of a connection that appears to be from a valid enclave. This vulnerability has been addressed in version wasm-v0.40.0.

Affected Version(s)

enclave-os-mini < wasm-v0.40.0

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.