---
id: CVE-2026-6726
title: >-
  An information leakage vulnerability was reported in the TCG TPM 2.0 reference
  code that could allow a local attacker with elevated privileges to obtain a
  credential from a TPM-aware CA for a falsified TPM key (such as an Attestation
  Key…
summary: >-
  An information leakage vulnerability was reported in the TCG TPM 2.0 reference
  code that could allow a local attacker with elevated privileges to obtain a
  credential from a TPM-aware CA for a falsified TPM key (such as an Attestation
  Key…
severity: high
cvss: 7.9
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'
cwe:
  - CWE-704
published: '2026-08-11'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T14:09:00.860'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-6726'
references:
  - url: >-
      https://trustedcomputinggroup.org/resource/errata-for-tpm-library-specification-2-0/
    label: cret@cert.org
  - url: >-
      https://trustedcomputinggroup.org/wp-content/uploads/Extended-vrt0010-11-guidance_V1.pdf
    label: cret@cert.org
  - url: >-
      https://trustedcomputinggroup.org/wp-content/uploads/VRT0010-Advisory_Final-1.pdf
    label: cret@cert.org
tags:
  - nvd
epss: 0.00215
epssPercentile: 0.12133
ingestedAt: '2026-09-08T15:33:26.952Z'
---

## Overview

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key.  See also TCG VRT0010.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
