Description
An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.
Published: 2026-08-11
Score: 7.9 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an information leakage in the TCG TPM 2.0 reference code that lets a local attacker with elevated privileges extract a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key). With this credential the attacker can forge TPM 2.0 attestations, effectively compromising the integrity of services that rely on TPM attestations. This weakness corresponds to improper type conversion or cast (CWE-704).

Affected Systems

The impact is limited to implementations that use the Trusted Computing Group TPM 2.0 reference code. No specific release numbers are listed; therefore any instance of the reference code that has not been updated to the latest patch set may be vulnerable. The vulnerability applies to all products that rely on this reference code for TPM key handling and attestation.

Risk and Exploitability

The flaw is local; the attacker must have privileged or elevated local access. The CVSS score of 7.9 indicates a high severity. EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet seen widespread exploitation. Nonetheless, the ability to forge attestations could severely undermine security controls that rely on TPM attestations. Despite the low exploitation probability, the impact on integrity is significant, making it a high risk for systems that rely on TPM for authentication or attestation.

Generated by OpenCVE AI on August 13, 2026 at 04:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch to the TCG TPM 2.0 reference code that addresses the credential leakage issue.
  • Limit local privileged access and enforce least privilege for users who can run code with elevated rights.
  • Monitor TPM key usage and audit credential files; investigate any anomalous key generation or usage.

Generated by OpenCVE AI on August 13, 2026 at 04:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Trustedcomputinggroup
Trustedcomputinggroup tpm2.0
Vendors & Products Trustedcomputinggroup
Trustedcomputinggroup tpm2.0

Thu, 13 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-269

Wed, 12 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-704
Metrics cvssV3_1

{'score': 7.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-269

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.
Title An information leakage vulnerability in the TCG TPM 2.0 reference code.
References

Subscriptions

Trustedcomputinggroup Tpm2.0
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-08-12T19:18:15.598Z

Reserved: 2026-04-20T21:17:45.860Z

Link: CVE-2026-6726

cve-icon Vulnrichment

Updated: 2026-08-12T19:16:36.949Z

cve-icon NVD

Status : Received

Published: 2026-08-11T16:17:34.397

Modified: 2026-08-12T20:17:49.180

Link: CVE-2026-6726

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:54:17Z

Weaknesses
  • CWE-704

    Incorrect Type Conversion or Cast