Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-92702: Cocos AI can mistakenly trust invalid secure‑enclave proof

CVE-2026-92702 · published 21 days ago
Summary

Versions of Cocos AI up to 0.8.2 may accept a proof that a protected hardware environment is in place even when that proof is old or unrelated, if no specific data is supplied. This could let an attacker appear trusted and gain access to AI workloads. Upgrade to version 0.9.0 or later to enforce proper checking.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ultravioletrs cocos < 0.9.0
Original advisory text
Cocos AI: Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path
Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) AMD SEV-SNP verification path does not enforce attestation freshness when the expected reportData value is nil, empty, or omitted, leaving the SEV-SNP policy ReportData unset so the verifier accepts unrelated or stale Evidence not bound to the current connection. A relying party that uses this path without an expected reportData as a trust or authorization decision can be induced to trust an unintended attestation context; a supplied non-empty reportData is still validated. The issue is fixed in version 0.9.0.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-346Origin Validation Error
Timeline
Published18 Sep 2026
Updated9 Oct 2026
First seen18 Sep 2026
Sources
CVE-2026-92702 · MITRE
Track software like this
Free during beta