Information Leakage Vulnerability in TCG TPM 2.0 Reference Code by Trusted Computing Group
CVE-2026-6726

Currently unrated

Key Information:

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-6726?

An information leakage vulnerability has been identified in the TCG TPM 2.0 reference code. This flaw may allow a local attacker with elevated privileges to acquire sensitive credentials from a TPM-aware Certification Authority (CA), utilizing falsified TPM keys such as Attestation Keys, DevID Keys, or TLS authentication keys. This could lead to the potential falsification of other TPM 2.0 attestations, raising significant security concerns for systems relying on trusted platform modules. For further technical details, refer to the advisories linked in the Trusted Computing Group resources.

Affected Version(s)

TPM2.0 0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.