{"id":"CVE-2026-14296","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-14296","summary":"When using the Direct XIP\nupdate strategy, the main application image starts other cores (i.e. radio\ncore), based on the currently active slot without additional verification. The\nMCUboot…","details":"When using the Direct XIP\nupdate strategy, the main application image starts other cores (i.e. radio\ncore), based on the currently active slot without additional verification. The\nMCUboot in the bare (upstream) configuration assumes that if there is at least\na single slot for each image available, the system is bootable and continues\nthe boot process. This may lead to a situation when MCUboot picks different\nslot for different images (i.e. (a) for the main application and (b) for the\nradio image), boots the main application (from slot (a)) that afterwards starts\nthe radio image by providing an address of the unauthenticated slot ((a)\ninstead of (b)).","published":"2026-09-07T08:17:11.773","modified":"2026-09-07T08:17:11.773","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://docs.nordicsemi.com/r/bundle/struct_sa/page/struct/sa.html"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-07T08:17:11.773"}}