CVE-2026-92702
Last modified
CVE-2026-92702 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) AMD SEV-SNP verification path does not enforce attestation freshness when the expected reportData value is nil, empty, or omitted, leaving the SEV-SNP policy ReportData unset so the verifier accepts unrelated or stale Evidence not bound to the current connection.
Description
Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) AMD SEV-SNP verification path does not enforce attestation freshness when the expected reportData value is nil, empty, or omitted, leaving the SEV-SNP policy ReportData unset so the verifier accepts unrelated or stale Evidence not bound to the current connection. A relying party that uses this path without an expected reportData as a trust or authorization decision can be induced to trust an unintended attestation context; a supplied non-empty reportData is still validated. The issue is fixed in version 0.9.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| ultravioletrs | cocos | < 0.9.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-92702?
How severe is CVE-2026-92702?
How do I fix CVE-2026-92702?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9265Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits…9.1
- CVE-2026-9266A Missing Required Cryptographic Step vulnerability has been…7
- CVE-2026-9267Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f…6.9
- CVE-2026-9269The Secure Copy Content Protection and Content Locking WordP…3.5
- CVE-2026-9270DataDog::DogStatsd versions through 0.07 for Perl allow metr…9.1
- CVE-2026-92701trusted execution environments. In versions up to and includ…9.1
- CVE-2026-92708Svelte devalue is a JavaScript library that serializes value…7.5
- CVE-2026-9271Vulnerability Title5.9
- CVE-2026-92714The Download Manager plugin for WordPress is vulnerable to I…6.5
- CVE-2026-92716Shuffle through 2.2.1 contains a cross-tenant privilege esca…9.6
- CVE-2026-92717Covenant through 0.6 registers the CovenantHub SignalR hub w…9.1
- CVE-2026-92718Nuclei versions before 3.11.1 cache template signature verif…7.3
Are you affected by CVE-2026-92702?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
