{"id":"CVE-2026-6726","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-6726","summary":"An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware…","details":"An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key.  See also TCG VRT0010.","published":"2026-08-11T16:17:34.397","modified":"2026-08-12T20:17:49.180","cvss":{"score":7.9,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://trustedcomputinggroup.org/resource/errata-for-tpm-library-specification-2-0/"},{"type":"WEB","url":"https://trustedcomputinggroup.org/wp-content/uploads/Extended-vrt0010-11-guidance_V1.pdf"},{"type":"WEB","url":"https://trustedcomputinggroup.org/wp-content/uploads/VRT0010-Advisory_Final-1.pdf"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T20:17:49.180"}}