Description
OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute unconditionally. Attackers can bypass attestation verification by including the test_purpose key in evidence and providing enrolled measure and serial number pairs from the allowlist to gain unauthorized access.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Update
AI Analysis

Impact

The vulnerability in OpenNHP allows an attacker to supply evidence that includes a test_purpose key, causing the system to unconditionally use the FallbackVerifier. As a result, the authentication verification can be bypassed, enabling the attacker to present enrolled measurements and serial numbers from the allowlist and gain unauthorized access. This flaw is a classic authentication bypass.

Affected Systems

The affected software is OpenNHP (the Opennhp project) and all releases up to and including version 1.0.2. Versions newer than 1.0.2 are not affected as the verifier selection logic has been corrected.

Risk and Exploitability

With a CVSS score of 8.7, the vulnerability is considered high severity. The EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis, and the vulnerability is not listed in CISA KEV. Attackers likely need to interact with the application’s evidence submission endpoint, so the attack vector is inferred to be remote over the network. The flaw permits bypass of attestation validation, but no execution or privilege escalation beyond unauthorized access is described in the data.

Generated by OpenCVE AI on September 18, 2026 at 06:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenNHP to a release newer than 1.0.2 where the verifier selection logic is fixed.
  • If an upgrade is not immediately possible, reconfigure the application to disable or restrict the use of the FallbackVerifier and ensure only trusted verifiers are invoked.
  • Ensure that evidence submitted to the system does not contain the test_purpose key or is validated to prevent this bypass.

Generated by OpenCVE AI on September 18, 2026 at 06:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Opennhp
Opennhp opennhp
Vendors & Products Opennhp
Opennhp opennhp

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute unconditionally. Attackers can bypass attestation verification by including the test_purpose key in evidence and providing enrolled measure and serial number pairs from the allowlist to gain unauthorized access.
Title OpenNHP through 1.0.2 Authentication Bypass via Fallback Verifier
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T01:44:37.436Z

Reserved: 2026-09-16T19:40:19.806Z

Link: CVE-2026-92792

cve-icon Vulnrichment

Updated: 2026-09-19T01:44:21.849Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:28.780

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-92792

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:37:50Z

Weaknesses