Missing Authorization in Caliptra Core Runtime Firmware Affects Local Privileged Users
CVE-2026-7328

6.8MEDIUM

Key Information:

Vendor

Caliptra

Vendor
CVE Published:
22 July 2026

What is CVE-2026-7328?

The Caliptra Core Runtime Firmware is susceptible to a missing authorization vulnerability. In subsystem mode, this flaw enables privileged local attackers to exploit the system by executing mailbox commands with unverified AXI addresses. This exploitation can lead to a denial of service, impacting system availability. Users should take precautionary measures to secure their environments against potential exploitation through this firmware.

Affected Version(s)

Core Runtime Firmware 2.1.0

Core Runtime Firmware 2.1.1

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.