CVE-2026-14296
Last modified
CVE-2026-14296 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. When using the Direct XIP update strategy, the main application image starts other cores (i.e. radio core), based on the currently active slot without additional verification. EPSS estimates a 0.11% chance of exploitation in the next 30 days.
Description
When using the Direct XIP update strategy, the main application image starts other cores (i.e. radio core), based on the currently active slot without additional verification. The MCUboot in the bare (upstream) configuration assumes that if there is at least a single slot for each image available, the system is bootable and continues the boot process. This may lead to a situation when MCUboot picks different slot for different images (i.e. (a) for the main application and (b) for the radio image), boots the main application (from slot (a)) that afterwards starts the radio image by providing an address of the unauthenticated slot ((a) instead of (b)).
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Nordic Semiconductor ASA | nRF54H20 | 3.2; 3.3 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-14296?
How severe is CVE-2026-14296?
How do I fix CVE-2026-14296?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-14289The FacturaONE para WooCommerce con VeriFactu WordPress plug…9
- CVE-2026-1429Single Sign-On Portal System developed by WellChoose has a R…5.4
- CVE-2026-14290The Embed Google Photos album WordPress plugin through 2.2.1…6.8
- CVE-2026-14291The security-ninja-premium WordPress plugin before 5.290 doe…7.5
- CVE-2026-14292The Download Manager WordPress plugin before 3.3.66 does not…5.4
- CVE-2026-14293The Autopay WordPress plugin before 5.0.1 does not perform a…8.8
- CVE-2026-14297A buffer overflow in the Bluetooth Continuous Glucose M…8.7
- CVE-2026-14298Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7…6.5
- CVE-2026-1430The WP Lightbox 2 WordPress plugin before 3.0.7 does not san…4.8
- CVE-2026-14300The miniOrange Social Login and Register (Discord, Google, T…8.1
- CVE-2026-14304In Eclipse Accessibility Tools Framework (ACTF) versions up …5.5
- CVE-2026-14305The WP Delicious WordPress plugin before 1.10.2 does not pe…5.3
Are you affected by CVE-2026-14296?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
