The CVE-2026-11836 record describes a vulnerability in Caliptra Core ROM and Core Firmware, specifically in the validate_debug_unlock_token() function. This function insufficiently verifies data authenticity, allowing an attacker with access to the integrator's debug unlock signing service to unlock production debug on an unintended device. The vulnerability affects Core ROM versions 2.0.0 through 2.0.2 a [truncated]
A time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mode allows a compromised local attacker to silently bypass secure boot by supplying an AXI staging address that is not validated against the strap-configured SS_EXTERNAL_STAGING_AREA_BASE_ADDR, enabling firmware to be modified between verification and loadin [truncated]
A medium-severity vulnerability was found in Caliptra Core Runtime Firmware version 2.1.0. The issue is caused by missing authorization for INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, and EXTERNAL_MAILBOX_CMD commands in subsystem mode. This allows a privileged local attacker to cause a denial of service via mailbox commands containing unverified AXI addresses. The security impact beyond availability is i [truncated]
A medium severity vulnerability, CVE-2026-6458, was found in Caliptra Core Firmware. The issue arises from a missing cryptographic step in the aes_256_gcm_update module, resulting in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with empty AAD, the hardware GHASH accumulator state is not saved after the first update call, causing the final tag to exclude the first batch o [truncated]