Weakness in On-the-Fly Decryption for nRF5340 Flash Encryption by Nordic Semiconductor
CVE-2026-18796

6.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-18796?

The vulnerability affects the nRF5340 platform, particularly concerning the external QSPI flash used for encrypted execute-in-place (XIP) operations. Applications utilizing this setup may be at risk if they depend on the encryption for maintaining confidentiality and integrity of externally stored code. The root of the issue lies in the on-the-fly decryption scheme, which could allow unauthorized access to sensitive information, warranting close attention and proper countermeasures.

Affected Version(s)

nRF5340 All build codes

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reported externally through PSIRT by Daniël Eijkmann and Damian Vizár (CSEM)
.