CVE-2026-18796: QSPI flash encryption side-channel leakage
Published Sep 7, 2026
·Updated
Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally stored code. No specific nRF Connect SDK version is the root cause; the weakness is in the on-the-fly decryption scheme.
Affected Software
1 affected component
nRF5340 (QSPI flash encryption for encrypted XIP)
Event History
Sep 7, 2026
CVE Published
via MITRE·08:07 AM
Data Sourced
via MITRE·08:07 AM
DescriptionWeakness
Frequently Asked Questions
1
Does updating to a particular nRF Connect SDK version resolve this issue?
No specific nRF Connect SDK version is identified as the root cause. The weakness is in the on-the-fly decryption scheme used for QSPI flash encryption.
2
How can I determine whether an application should be treated as affected?
Treat it as affected if it runs on nRF5340, uses external QSPI flash for encrypted execute-in-place (XIP), and depends on that encryption to provide confidentiality or integrity for externally stored code.