CVE-2026-100835: Contrast before 1.16.0 Remote Attestation Relay Attack
Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and software measurements, regardless of which machine produced it, so attestation was not bound to specific, physically trusted hardware. An attacker who can both intercept network traffic between the CLI and the Coordinator (or between the Coordinator and an attested component) and forge reports or extract secrets from any single TEE machine under their physical control can relay such a report to impersonate a Contrast Coordinator or a Contrast workload, defeating identity verification in Contrast's attested TLS (aTLS).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Contrastto a version that resolves this vulnerability.Fixed in 1.16.0
Event History
Frequently Asked Questions
What conditions must an attacker meet to exploit this issue?
The attacker must be able to intercept traffic between the CLI and Coordinator or between the Coordinator and an attested component. They must also be able to forge attestation reports or extract secrets from at least one TEE machine under their physical control.
Is a remotely reachable Contrast deployment affected by network access alone?
No. Although the affected communications are networked, exploitation also requires a valid relay source: forged reports or secrets obtained from a TEE machine physically controlled by the attacker.
What security property can fail if exploitation succeeds?
An attacker can relay an otherwise valid attestation report to impersonate a Contrast Coordinator or Contrast workload. This defeats identity verification performed by Contrast's attested TLS (aTLS).
Which deployments should be prioritized for remediation?
Prioritize Contrast installations before 1.16.0 that use aTLS and operate over network paths where an attacker could intercept CLI-to-Coordinator or Coordinator-to-component traffic. Environments relying on attestation to establish the identity of Coordinators or workloads are directly relevant.