CVE-2026-6726
HIGH
7,9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Attack Vector: local
Attack Complexity: low
Privileges Required: high
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: high
Availability: none
Description
AI Translation Available
An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.
704
Incorrect Type Conversion or Cast
IncompleteCommon Consequences
Security Scopes Affected:
Other
Potential Impacts:
Other
Applicable Platforms
Languages:
C, C++, Not Language-Specific, Memory-Unsafe
https://trustedcomputinggroup.org/resource/errata-for-tpm-library-specification…
https://trustedcomputinggroup.org/wp-content/uploads/Extended-vrt0010-11-guidan…
https://trustedcomputinggroup.org/wp-content/uploads/VRT0010-Advisory_Final-1.p…