Missing Authorization in Caliptra Core Runtime Firmware Affects Local Privileged Users
CVE-2026-7328
6.8MEDIUM
What is CVE-2026-7328?
The Caliptra Core Runtime Firmware is susceptible to a missing authorization vulnerability. In subsystem mode, this flaw enables privileged local attackers to exploit the system by executing mailbox commands with unverified AXI addresses. This exploitation can lead to a denial of service, impacting system availability. Users should take precautionary measures to secure their environments against potential exploitation through this firmware.
Affected Version(s)
Core Runtime Firmware 2.1.0
Core Runtime Firmware 2.1.1
