PatchSiren cyber security CVE debrief
CVE-2026-18796 Nordic Semiconductor ASA CVE debrief
A vulnerability in the on-the-fly decryption scheme used for encrypted XIP on nRF5340 devices that rely on external QSPI flash may allow confidentiality and/or integrity impacts on externally stored code. The issue arises from the specific implementation of the decryption scheme, which could be exploited under certain conditions. This vulnerability affects applications that use external QSPI flash for encrypted XIP on nRF5340 devices. The weakness is not specific to any nRF Connect SDK version but is inherent in the decryption scheme itself.
- Vendor
- Nordic Semiconductor ASA
- Product
- nRF5340
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-07
- Original CVE updated
- 2026-09-07
- Advisory published
- 2026-09-07
- Advisory updated
- 2026-09-07
Who should care
Defenders and developers responsible for nRF5340 device configurations, secure coding practices, and external QSPI flash interactions should assess exposure and prioritize verification.
Why it matters
Defenders should assess exposure and prioritize verification of decryption scheme usage and external QSPI flash reliance in nRF5340 devices, as the vulnerability may impact confidentiality and integrity of externally stored code.
- Potential confidentiality impacts on externally stored code.
- Potential integrity impacts on externally stored code.
- Verification priority for decryption scheme usage and external QSPI flash reliance.
Technical summary
The vulnerability affects applications using external QSPI flash for encrypted XIP on nRF5340 devices, potentially impacting confidentiality and integrity of externally stored code. The issue arises from the specific implementation of the on-the-fly decryption scheme. This weakness is not specific to any nRF Connect SDK version but is inherent in the decryption scheme itself. The vulnerability may allow confidentiality and/or integrity impacts on externally stored code under certain conditions. Defenders should assess exposure and prioritize verification of decryption scheme usage and external QSPI flash reliance in nRF5340 devices.
Defensive priority
Defenders should assess exposure and prioritize verification of decryption scheme usage and external QSPI flash reliance in nRF5340 devices.
Recommended defensive actions
- Assess nRF5340 device configurations for external QSPI flash usage and encrypted XIP reliance.
- Verify decryption scheme usage and potential impacts on confidentiality and integrity.
- Review and update secure coding practices for external QSPI flash interactions.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE description indicates that the weakness is in the on-the-fly decryption scheme used for encrypted XIP on nRF5340 devices that rely on external QSPI flash. The vulnerability may impact confidentiality and/or integrity of externally stored code. The issue is not related to a specific nRF Connect SDK version but is a result of the decryption scheme's implementation. Defenders should verify the usage of this scheme and its potential impacts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-18796 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-18796
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-18796 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18796
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://docs.nordicsemi.com/r/bundle/struct_sa/page/struct/sa.html
30a5e7fb-040d-440a-8cdf-a4a2068ce72e
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.