CVE-2026-6726

Published: Ago 11, 2026 Last Modified: Ago 12, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Attack Vector: local
Attack Complexity: low
Privileges Required: high
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: high
Availability: none

Description

AI Translation Available

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.

704

Incorrect Type Conversion or Cast

Incomplete
Common Consequences
Security Scopes Affected:
Other
Potential Impacts:
Other
Applicable Platforms
Languages: C, C++, Not Language-Specific, Memory-Unsafe
View CWE Details
https://trustedcomputinggroup.org/resource/errata-for-tpm-library-specification…
https://trustedcomputinggroup.org/wp-content/uploads/Extended-vrt0010-11-guidan…
https://trustedcomputinggroup.org/wp-content/uploads/VRT0010-Advisory_Final-1.p…