CVE-2026-72714
Last modified
CVE-2026-72714 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled the check is closed. Local Unset Universe Checking inside a module is expected to last only until the module ends, and the global flag is restored, but the universe graph keeps its own copy which is left disabled. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled the check is closed. Local Unset Universe Checking inside a module is expected to last only until the module ends, and the global flag is restored, but the universe graph keeps its own copy which is left disabled. The two views then disagree: Test Universe Checking reports the check as enabled while the kernel continues to accept universe-inconsistent terms. With the constraint between two universes no longer enforced, Hurkens' paradox applies and yields a proof of False, from which any proposition follows. The proof uses no axioms, plugins or unsafe features once the module has closed, and Print Assumptions reports it as closed under the global context, so neither the assumption audit nor the flag query reflects the actual kernel state. No fix is available.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| rocq-prover | rocq | <= 9.2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-72714?
How severe is CVE-2026-72714?
How do I fix CVE-2026-72714?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-72709SPIP before version 4.4.18 contains a missing authorization …9.8
- CVE-2026-7271A vulnerability was detected in DV0x creative-ad-agent up to…5.5
- CVE-2026-72710SPIP before 4.4.18 contains a mass assignment vulnerability …9.8
- CVE-2026-72711The Lean 4 kernel does not check that the body of an opaque …6.3
- CVE-2026-72712Nmap versions up to and including 7.99 contains a denial of …6.5
- CVE-2026-72713XAgent contains a path traversal vulnerability in the worksp…7.5
- CVE-2026-72716Orval generates type-safe JavaScript clients in TypeScript f…9.3
- CVE-2026-72717Orval generates type-safe JavaScript clients in TypeScript f…9.3
- CVE-2026-72718goose is general-purpose AI agent that runs on your machine.…7
- CVE-2026-72719Chatwoot is a customer engagement suite. Prior to 4.9.0, Cha…6.7
- CVE-2026-7272A flaw has been found in WilliamCloudQi matlab-mcp-server up…7.3
- CVE-2026-72720Discourse is an open-source discussion platform. Prior to 20…6.4
Are you affected by CVE-2026-72714?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
