CVE-2026-18796
6.8
CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N
Summary
Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally stored code. No specific nRF Connect SDK version is the root cause; the weakness is in the on-the-fly decryption scheme.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Nordic Semiconductor ASA | nRF5340 | All build codes | affected |
Weaknesses
- CWE-1342: CWE-1342 Information exposure through microarchitectural state after transient execution
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.