CVE-2026-24088: Missing Authentication for Critical Function in Boot
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Enable authentication for critical boot functions so that any operation that modifies or writes the boot partition requires proper authentication/authorization to prevent unauthorized write access and loading of a customized bootloader.
Boot / boot partition authentication for critical boot functions = enabled - Configuration
Enforce cryptographic validation (digital signature verification) of the bootloader and contents of the boot partition before allowing them to be written or executed to mitigate the reported cryptographic issue.
Boot / boot partition cryptographic verification of bootloader = enabled - Compensating control
Restrict write access to the affected partition and firmware update interfaces to trusted administrators only, apply access controls/ACLs, and ensure physical security of devices to prevent unauthorized modifications while fixes are implemented.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24088?
The severity of CVE-2026-24088 is high, with a score of 8.2.
What is the main issue described in CVE-2026-24088?
CVE-2026-24088 involves a missing authentication for critical functions in boot, allowing unauthorized write access to load a customized bootloader.
How do I fix CVE-2026-24088?
To address CVE-2026-24088, users should apply the available patch provided by Qualcomm.
Which software is affected by CVE-2026-24088?
CVE-2026-24088 affects several Qualcomm firmware versions including Ar9380, Csr8811, Fastconnect 6200, 6700, 6900, 7800, G1 Gen 1, and G2 Gen 1.
When was CVE-2026-24088 published?
CVE-2026-24088 was published on June 1, 2026.