---
id: CVE-2026-100835
title: Contrast before 1.16.0 is susceptible to remote attestation relay attacks
summary: >-
  Contrast before 1.16.0 is susceptible to remote attestation relay attacks.
  Contrast accepted any TEE attestation report that verified correctly and
  contained the expected firmware patch levels and software measurements,
  regardless of whi…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-295
vendor: edgelesssys
product: contrast
affected:
  - contrast < 1.16.0
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T02:17:21.640'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100835'
references:
  - url: >-
      https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/contrast-before-1.16.0-remote-attestation-relay-attack
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T02:41:45.570Z'
---

## Overview

Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and software measurements, regardless of which machine produced it, so attestation was not bound to specific, physically trusted hardware. An attacker who can both intercept network traffic between the CLI and the Coordinator (or between the Coordinator and an attested component) and forge reports or extract secrets from any single TEE machine under their physical control can relay such a report to impersonate a Contrast Coordinator or a Contrast workload, defeating identity verification in Contrast's attested TLS (aTLS).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
