Skip to main content
Vulnerability Database/CVE-2026-100835

CVE-2026-100835: Contrast Remote Attestation Relay Bypass

CVE-2026-100835 is an authentication bypass in Contrast before 1.16.0 allowing remote attestation relay attacks. Attackers can impersonate Coordinators or workloads by relaying TEE reports. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-100835 Overview

CVE-2026-100835 is a remote attestation relay vulnerability affecting Contrast versions prior to 1.16.0. Contrast is a confidential computing platform from Edgeless Systems that uses Trusted Execution Environment (TEE) attestation to verify workload identity. The vulnerability stems from Contrast accepting any TEE attestation report that verified correctly and contained the expected firmware patch levels and software measurements, without binding attestation to specific trusted hardware. Attackers who intercept network traffic and control any single TEE machine can relay valid reports to impersonate a Contrast Coordinator or workload. This defeats identity verification in Contrast's attested TLS (aTLS) channel.

Critical Impact

An attacker able to intercept traffic between the Contrast command-line interface (CLI) and the Coordinator, and who controls any single TEE device, can impersonate trusted components and compromise confidentiality and integrity of attested communications.

Affected Products

  • Edgeless Systems Contrast versions prior to 1.16.0
  • Contrast Coordinator component
  • Contrast workloads using attested TLS (aTLS)

Discovery Timeline

  • 2026-09-27 - CVE-2026-100835 published to the National Vulnerability Database (NVD)
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-100835

Vulnerability Analysis

The flaw is classified as improper certificate validation [CWE-295] within Contrast's attestation workflow. Contrast relies on TEE attestation reports to establish trust in Coordinator and workload identities before establishing attested TLS sessions. The verification logic checks that the attestation report is cryptographically valid, matches expected firmware patch levels, and contains the expected software measurements. However, it does not bind the report to a specific physical device or enrolled hardware identity.

Because of this missing binding, any attestation report produced by any TEE machine satisfying those criteria is treated as authentic. An attacker who extracts secrets from a single TEE under their physical control can produce reports that pass verification. When combined with a network position between the CLI and Coordinator, or between the Coordinator and an attested component, the attacker can inject these reports and complete the aTLS handshake while impersonating a trusted party.

Root Cause

The root cause is the absence of hardware identity binding during attestation report verification. Contrast's verifier accepts semantically valid reports without checking whether they originated from an enrolled, physically trusted device.

Attack Vector

Exploitation requires two conditions. First, the attacker must achieve a network interception position between Contrast components. Second, the attacker must possess physical control of at least one TEE machine capable of producing valid attestation reports or extracting attestation secrets. With both in place, the attacker relays or forges reports to impersonate the Coordinator or workloads. Refer to the GitHub Security Advisory GHSA-hjgc-jc5v-fw7h and the VulnCheck Advisory on Remote Attestation Attack for additional technical context.

Detection Methods for CVE-2026-100835

Indicators of Compromise

  • Unexpected aTLS session establishment from Coordinator or workload identities originating from unknown network locations.
  • Attestation reports verified by the Coordinator that reference TEE hardware instances outside the known deployment inventory.
  • Anomalous CLI-to-Coordinator traffic patterns consistent with man-in-the-middle (MITM) interception.

Detection Strategies

  • Correlate attestation verification logs with an authoritative inventory of enrolled TEE hardware identifiers and alert on mismatches.
  • Monitor for duplicate attestation evidence appearing from multiple source addresses within short time windows.
  • Baseline the network paths used by Contrast CLI, Coordinator, and workload communication, and alert on route or TLS fingerprint deviations.

Monitoring Recommendations

  • Ingest Contrast Coordinator attestation logs into a centralized analytics pipeline for continuous review.
  • Audit certificate chains and attestation report metadata during every aTLS handshake.
  • Track changes to firmware patch levels and software measurements across workloads to identify report replay or substitution.

How to Mitigate CVE-2026-100835

Immediate Actions Required

  • Upgrade Contrast to version 1.16.0 or later across all Coordinator and workload components.
  • Rotate any secrets, keys, or certificates that may have transited aTLS sessions established on vulnerable versions.
  • Restrict network paths between the Contrast CLI, Coordinator, and workloads to trusted segments to reduce interception opportunity.

Patch Information

Edgeless Systems addressed the issue in Contrast 1.16.0. The fix introduces binding of attestation verification to specific trusted hardware so that semantically valid reports from unauthorized TEE devices are rejected. Review the GitHub Security Advisory GHSA-hjgc-jc5v-fw7h for upgrade guidance.

Workarounds

  • Enforce strict network segmentation and mutual authentication at the transport layer to limit MITM opportunities until the upgrade is deployed.
  • Operate Contrast Coordinator and workloads only on hardware under direct physical control and in trusted facilities.
  • Monitor all attestation events and manually validate hardware identifiers until the patched release is in production.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.