{"id":"CVE-2026-92792","title":"OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute unconditionally","summary":"OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute unconditionally. Attackers can bypass attestation verific…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-287"],"vendor":"OpenNHP","product":"opennhp","affected":["opennhp <= 1.0.2"],"published":"2026-09-16","updated":"2026-09-19","sourceUpdated":"2026-09-19T02:16:54.680","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92792","references":[{"url":"https://github.com/OpenNHP/opennhp","label":"disclosure@vulncheck.com"},{"url":"https://github.com/OpenNHP/opennhp/blob/v1.0.2/nhp/core/verifier/verifier.go#L27-L92","label":"disclosure@vulncheck.com"},{"url":"https://github.com/OpenNHP/opennhp/issues/1732","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/opennhp-through-1.0.2-authentication-bypass-via-fallback-verifier","label":"disclosure@vulncheck.com"},{"url":"https://github.com/OpenNHP/opennhp/issues/1732","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-19T01:44:00.477221Z"},"epss":0.00453,"epssPercentile":0.38565,"ingestedAt":"2026-09-16T21:05:36.887Z","slug":"CVE-2026-92792","body":"## Overview\n\nOpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute unconditionally. Attackers can bypass attestation verification by including the test_purpose key in evidence and providing enrolled measure and serial number pairs from the allowlist to gain unauthorized access.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":207562,"id":"CVE-2026-92792","ts":1789782988690,"field":"exploit_available","old":"false","new":"true"}]}