Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6420

26
FAUCET Score

A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation instead of a cryptographically random value. This allows the attacker to stockpile valid TPM quotes and replay them to evade detection after compromising the system. This issue affects only the push model deployment.

First published: May 6, 2026Last modified: Jun 24, 2026

Impacted Technologies

VendorProductVersion(s)CPE
Red HatRed Hat Enterprise Linux 10
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 9
All Versions ImpactedCNA affecteddefault affected

CVSS Data

CVSS version used by this source: 3.1

6.3MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
0.8
Impact Score
5.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.12%
Probability of exploitation in next 30 days
EPSS Percentile
2.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0012 is in the 26th percentile among its peer group of 3,720 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

pippatch availablevia ghsa
Product: keylimeFixed in: 7.14.2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: keylime
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: keylime

Vendor Advisories (2)

pipGHSA-q8w6-w55c-ccv5medium

Keylime has a hardcoded attestation challenge nonce that allows replay attacks

May 11, 2026
redhatCVE-2026-6420Moderate

keylime: Keylime: Security bypass due to hardcoded TPM quote nonce

May 6, 2026

References

access.redhat.com / errata/RHSA-2026:28582
access.redhat.com / security/cve/CVE-2026-6420
bugzilla.redhat.com / show_bug.cgi