CVE-2026-6420

MEDIUM

CVSS v3.1: 6.3 · EPSS: 0.0011 (1.8 percentile)

No user interaction

Source data as of:

At a glance

Severity
MEDIUM
CVSS
6.3 v3.1 · NVD
EPSS
0.0011 (1.8 percentile) · FIRST.org
CISA KEV
No
Attack conditions (CVSS vector)
No user interaction · Source: NVD Vector
Published
2026-05-06 · Modified: 2026-06-24

CVSS / EPSS / KEV

CVSS v3.1 6.3 / 10 MEDIUM Source: NVD
EPSS 0.0011 1.8 percentile Source: FIRST.org
CISA KEV No Source: CISA

Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources

Description

A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation instead of a cryptographically random value. This allows the attacker to stockpile valid TPM quotes and replay them to evade detection after compromising the system. This issue affects only the push model deployment.

Record details

CVE ID
CVE-2026-6420
CVSS (v3.1)
6.3 (MEDIUM)
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Exploitability subscore
0.8
Impact subscore
5.5
EPSS
0.0011 (1.8 percentile) — 2026-06-24
CISA KEV
No
Weakness (CWE)
CWE-1241
Affected configurations (CPE)
0
Published
2026-05-06
Modified
2026-06-24
Status
Awaiting Analysis

References

Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.