CVE-2026-11836

Source
https://cve.org/CVERecord?id=CVE-2026-11836
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-11836.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-11836
Aliases
  • GHSA-hw68-jjx4-m376
Published
2026-08-04T00:02:34.093Z
Modified
2026-08-07T11:48:51.670417002Z
Severity
  • 1.8 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Production Debug-Unlock Token Verification Missing Device Binding
Details

Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validatedebugunlock_token()) in subsystem mode allows an attacker with access to the integrator's debug unlock signing service to unlock production debug on an unintended device by presenting a valid token issued for a different device sharing the same debug unlock key hash. The 384-bit challenge nonce continues to prevent replay of previously issued tokens. Practical impact is limited to loss of per-device scope enforcement within a set of devices that share the same unlock authority by design; it does not enable debug unlock on devices outside that set.

This issue affects Core ROM: 2.0.0 through 2.0.2, 2.1.0 through 2.1.1; Core Firmware: 2.0.0 through 2.0.1, 2.1.0.

Database specific
{
    "cna_assigner": "Caliptra",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/11xxx/CVE-2026-11836.json",
    "cwe_ids": [
        "CWE-345"
    ]
}
References

Affected packages

Git / github.com/chipsalliance/caliptra-sw

Affected ranges

Type
GIT
Repo
https://github.com/chipsalliance/caliptra-sw
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "2.0.0"
        },
        {
            "fixed": "2.0.2"
        },
        {
            "fixed": "2.0.1"
        },
        {
            "introduced": "2.1.0"
        },
        {
            "fixed": "2.1.1"
        }
    ],
    "source": "DESCRIPTION"
}

Affected versions

fw-2.*
fw-2.0.0
fw-2.0.1
fw-2.1.0
release_v20251120_1-2.*
release_v20251120_1-2.x
release_v20251121_0-2.*
release_v20251121_0-2.x
release_v20251122_0-2.*
release_v20251122_0-2.x
release_v20251125_0-2.*
release_v20251125_0-2.x
release_v20251125_1-2.*
release_v20251125_1-2.x
release_v20251126_0-2.*
release_v20251126_0-2.x
release_v20251128_0-2.*
release_v20251128_0-2.x
release_v20251203_0-2.*
release_v20251203_0-2.x
release_v20251204_0-2.*
release_v20251204_0-2.x
release_v20260120_0-2.*
release_v20260120_0-2.0
release_v20260207_0-2.*
release_v20260207_0-2.0
release_v20260207_0-2.x
release_v20260207_1-2.*
release_v20260207_1-2.x
release_v20260208_0-2.*
release_v20260208_0-2.0
release_v20260209_0-2.*
release_v20260209_0-2.0
release_v20260210_0-2.*
release_v20260210_0-2.0
release_v20260214_0-2.*
release_v20260214_0-2.x
release_v20260217_0-2.*
release_v20260217_0-2.x
release_v20260218_0-2.*
release_v20260218_0-2.x
release_v20260303_0-2.*
release_v20260303_0-2.0
release_v20260310_0-2.*
release_v20260310_0-2.x
release_v20260310_1-2.*
release_v20260310_1-2.x
release_v20260312_0-2.*
release_v20260312_0-2.x
release_v20260317_0-2.*
release_v20260317_0-2.x
release_v20260319_0-2.*
release_v20260319_0-2.0
release_v20260319_0-2.x
release_v20260323_0-2.*
release_v20260323_0-2.0
rom-2.*
rom-2.0.0
rom-2.0.1
rom-2.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-11836.json"