Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerability · NVD

CVE-2026-6727

CVE-2026-6727 : medium severity (CVSS 5.9). No tracked catalog app is linked to this CVE.

Severity (CVSS)
5.9

NVD scale

Exploitation
0.2 %

EPSS, predicted over 30 days

Tracked apps
0
Still exposed
0

A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditions, this may also enable the forgery of TPM 2.0 attestations. Refer to TCGVRT0011.

Attack vector : Local No privileges required No user interaction
Show raw CVSS vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS 0.15% exploit very unlikely percentile 3.7%

OS versions that fix this CVE

This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.

View on NVD ↗

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM