critical · CVSS v3 7.4 · CVSS v4 9.1 · EPSS 0.00217
CVE-2026-100835
Contrast Security's Contrast platform before version 1.16.0 allows remote attestation relay attacks, enabling attackers to impersonate a tru
Overview
Contrast Security's Contrast platform before version 1.16.0 allows remote attestation relay attacks, enabling attackers to impersonate a trusted Coordinator or workload by relaying forged TEE attestation reports. This flaw bypasses the intended binding of attestation to specific hardware, undermining the integrity of Contrast's attested TLS (aTLS). The vulnerability can be exploited by intercepting traffic between the CLI and Coordinator or between the Coordinator and an attested component.
Description
Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and software measurements, regardless of which machine produced it, so attestation was not bound to specific, physically trusted hardware. An attacker who can both intercept network traffic between the CLI and the Coordinator (or between the Coordinator and an attested component) and forge reports or extract secrets from any single TEE machine under their physical control can relay such a report to impersonate a Contrast Coordinator or a Contrast workload, defeating identity verification in Contrast's attested TLS (aTLS).
Impact
The flaw compromises confidentiality, integrity, and availability of the attested TLS channel, allowing attackers to inject or eavesdrop on secure communications. Defenders using Contrast's aTLS for workload isolation are at risk of credential leakage and unauthorized access. The attack requires physical control of a TEE device and network interception, but once achieved, it can affect all components relying on attestation.
Remediation
Upgrade Contrast to version 1.16.0 or later where attestation reports are bound to the originating hardware. Verify that the Coordinator and CLI enforce strict TLS verification and reject reports from untrusted sources. Apply network segmentation to isolate CLI-Coordinator traffic and monitor for anomalous TLS handshakes. If upgrade is not possible, disable aTLS or enforce manual verification of TEE reports.
Risk context
The vulnerability is rated critical with CVSS v3 7.4 and v4 9.1, but its EPSS score of 0.00217 indicates a low probability of exploitation in the wild. Nonetheless, organizations relying on Contrast's attested TLS should prioritize patching due to the high impact on secure communications.
Affected products
- Contrast Security Contrast
- Contrast Security CLI
- Contrast Security Coordinator
- Contrast Security aTLS
Scores
- Severity
- critical
- CVSS v2
- 7.1
- CVSS v3
- 7.4
- CVSS v4
- 9.1
- EPSS
- 0.00217