Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-108265: Enclave OS Mini could allow connection hijack if key stolen

CVE-2026-108265 · published 1 day ago
Summary

Enclave OS Mini runs confidential code inside Intel SGX. If an attacker gets the TLS private key, they can reuse a trusted quote on a different connection, making a server think it is still talking to the original enclave. Update to version wasm‑v0.40.0 or later to fix the issue.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
privasys enclave-os-mini < wasm-v0.40.0
Original advisory text
enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session
Enclave OS Mini is a Rust-based runtime for confidential applications inside Intel SGX enclaves. Prior to wasm-v0.40.0, the SGX runtime's RA-TLS challenge certificate path placed the certificate public-key hash and client nonce in quote ReportData but omitted a value bound to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing a relying party to accept an attacker-terminated connection as the attested enclave. This issue is fixed in wasm-v0.40.0.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit (estimated)
  • Gives an attacker full control (estimated)
Severity
8.6 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-346Origin Validation Error
Timeline
Published9 Oct 2026
Updated11 Oct 2026
First seen9 Oct 2026
Sources
CVE-2026-108265 · MITRE
Track software like this
Free during beta