{"id":"CVE-2026-18796","title":"Any application that\n     uses external QSPI flash for encrypted XIP on nRF5340 and relies on that\n     encryption for confidentiality and/or integrity of the externally stored\n     code","summary":"Any application that\n     uses external QSPI flash for encrypted XIP on nRF5340 and relies on that\n     encryption for confidentiality and/or integrity of the externally stored\n     code. No specific nRF Connect SDK version is the root c…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N","cwe":["CWE-1342"],"vendor":"Nordic Semiconductor ASA","product":"nRF5340","affected":["nRF5340 All build codes"],"published":"2026-09-07","updated":"2026-09-09","sourceUpdated":"2026-09-09T15:50:19.447","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-18796","references":[{"url":"https://docs.nordicsemi.com/r/bundle/struct_sa/page/struct/sa.html","label":"30a5e7fb-040d-440a-8cdf-a4a2068ce72e"}],"tags":["nvd","cve.org"],"epss":0.00079,"epssPercentile":0.00178,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-08T15:01:20.642344Z"},"cvssSource":"cna","ingestedAt":"2026-09-08T15:33:26.975Z","slug":"CVE-2026-18796","body":"## Overview\n\nAny application that\n     uses external QSPI flash for encrypted XIP on nRF5340 and relies on that\n     encryption for confidentiality and/or integrity of the externally stored\n     code. No specific nRF Connect SDK version is the root cause; the weakness\n     is in the on-the-fly decryption scheme.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}