Remote Attestation Vulnerability in TLS Clients by PrivaSys
CVE-2026-108269

9.1CRITICAL

Key Information:

Vendor

Privasys

Vendor
CVE Published:
9 October 2026

What is CVE-2026-108269?

A vulnerability in the Remote Attestation TLS Clients allows attackers to relay genuine quotes onto different connections. This flaw exists due to the use of quote ReportData that is not properly bound to the active TLS session, potentially enabling attackers to present themselves as legitimate enclaves. The issue has been rectified in version 0.5.0, emphasizing the importance of updating to this version to enhance security.

Affected Version(s)

ra-tls-clients < 0.5.0

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.