CVE-2026-11836 PUBLISHED

Production Debug-Unlock Token Verification Missing Device Binding

Assigner: Caliptra
Reserved: 09.06.2026 Published: 04.08.2026 Updated: 04.08.2026

Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in subsystem mode allows an attacker with access to the integrator's debug unlock signing service to unlock production debug on an unintended device by presenting a valid token issued for a different device sharing the same debug unlock key hash. The 384-bit challenge nonce continues to prevent replay of previously issued tokens. Practical impact is limited to loss of per-device scope enforcement within a set of devices that share the same unlock authority by design; it does not enable debug unlock on devices outside that set.

This issue affects Core ROM: 2.0.0 through 2.0.2, 2.1.0 through 2.1.1; Core Firmware: 2.0.0 through 2.0.1, 2.1.0.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 1.8

Product Status

Vendor Caliptra
Product Core ROM
Versions Default: unaffected
  • affected from 2.0.0 to 2.0.2 (incl.)
  • Version 2.0.3 is unaffected
  • affected from 2.1.0 to 2.1.1 (incl.)
  • Version 2.1.2 is unaffected
Vendor Caliptra
Product Core Firmware
Versions Default: unaffected
  • affected from 2.0.0 to 2.0.1 (incl.)
  • Version 2.0.2 is unaffected
  • Version 2.1.0 is affected
  • Version 2.1.1 is unaffected

References

Problem Types

  • CWE-345 Insufficient Verification of Data Authenticity CWE

Impacts

  • CAPEC-115 Authentication Bypass