PatchSiren

OpenNHP CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH OpenNHP CVE published 2026-09-16

CVE-2026-92792

CVE-2026-92792 is a high-severity vulnerability in OpenNHP through 1.0.2, allowing attackers to bypass attestation verification. The vulnerability exists because OpenNHP selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute unconditionally. This could lead to unauthorized access if attackers provide enr [truncated]