CVE-2026-100835: Contrast before 1.16.0 Remote Attestation Relay Attack

Published Sep 27, 2026
·
Updated

Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and software measurements, regardless of which machine produced it, so attestation was not bound to specific, physically trusted hardware. An attacker who can both intercept network traffic between the CLI and the Coordinator (or between the Coordinator and an attested component) and forge reports or extract secrets from any single TEE machine under their physical control can relay such a report to impersonate a Contrast Coordinator or a Contrast workload, defeating identity verification in Contrast's attested TLS (aTLS).

Affected Software

1 affected component
Contrast Security Contrast<1.16.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Contrast to a version that resolves this vulnerability.

    Fixed in 1.16.0

Event History

Sep 27, 2026
CVE Published
via MITRE·01:28 AM
Data Sourced
via MITRE·01:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What conditions must an attacker meet to exploit this issue?

The attacker must be able to intercept traffic between the CLI and Coordinator or between the Coordinator and an attested component. They must also be able to forge attestation reports or extract secrets from at least one TEE machine under their physical control.

2

Is a remotely reachable Contrast deployment affected by network access alone?

No. Although the affected communications are networked, exploitation also requires a valid relay source: forged reports or secrets obtained from a TEE machine physically controlled by the attacker.

3

What security property can fail if exploitation succeeds?

An attacker can relay an otherwise valid attestation report to impersonate a Contrast Coordinator or Contrast workload. This defeats identity verification performed by Contrast's attested TLS (aTLS).

4

Which deployments should be prioritized for remediation?

Prioritize Contrast installations before 1.16.0 that use aTLS and operate over network paths where an attacker could intercept CLI-to-Coordinator or Coordinator-to-component traffic. Environments relying on attestation to establish the identity of Coordinators or workloads are directly relevant.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203