{"api_version":"1","generated_at":"2026-09-07T09:11:10+00:00","cve":"CVE-2026-14296","urls":{"html":"https://cve.report/CVE-2026-14296","api":"https://cve.report/api/cve/CVE-2026-14296.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-14296","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-14296"},"summary":{"title":"nRF54H20: MCUBoot can be tricked to executing unauthenticated code","description":"When using the Direct XIP\nupdate strategy, the main application image starts other cores (i.e. radio\ncore), based on the currently active slot without additional verification. The\nMCUboot in the bare (upstream) configuration assumes that if there is at least\na single slot for each image available, the system is bootable and continues\nthe boot process. This may lead to a situation when MCUboot picks different\nslot for different images (i.e. (a) for the main application and (b) for the\nradio image), boots the main application (from slot (a)) that afterwards starts\nthe radio image by providing an address of the unauthenticated slot ((a)\ninstead of (b)).","state":"PUBLISHED","assigner":"YesWeHack","published_at":"2026-09-07 08:17:11","updated_at":"2026-09-07 08:17:11"},"problem_types":["CWE-347","CWE-347 CWE-347 Improper verification of cryptographic signature"],"metrics":[{"version":"3.1","source":"30a5e7fb-040d-440a-8cdf-a4a2068ce72e","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"HIGH","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://docs.nordicsemi.com/r/bundle/struct_sa/page/struct/sa.html","name":"https://docs.nordicsemi.com/r/bundle/struct_sa/page/struct/sa.html","refsource":"30a5e7fb-040d-440a-8cdf-a4a2068ce72e","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-14296","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14296","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Nordic Semiconductor ASA","product":"nRF54H20","version":"affected 3.2","platforms":[]},{"source":"CNA","vendor":"Nordic Semiconductor ASA","product":"nRF54H20","version":"affected 3.3","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Reported externally through PSIRT","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"nRF54H20","vendor":"Nordic Semiconductor ASA","versions":[{"status":"affected","version":"3.2"},{"status":"affected","version":"3.3"}]}],"credits":[{"lang":"en","type":"reporter","value":"Reported externally through PSIRT"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<span>When using the Direct XIP\nupdate strategy, the main application image starts other cores (i.e. radio\ncore), based on the currently active slot without additional verification. The\nMCUboot in the bare (upstream) configuration assumes that if there is at least\na single slot for each image available, the system is bootable and continues\nthe boot process. This may lead to a situation when MCUboot picks different\nslot for different images (i.e. (a) for the main application and (b) for the\nradio image), boots the main application (from slot (a)) that afterwards starts\nthe radio image by providing an address of the unauthenticated slot ((a)\ninstead of (b)).</span>"}],"value":"When using the Direct XIP\nupdate strategy, the main application image starts other cores (i.e. radio\ncore), based on the currently active slot without additional verification. The\nMCUboot in the bare (upstream) configuration assumes that if there is at least\na single slot for each image available, the system is bootable and continues\nthe boot process. This may lead to a situation when MCUboot picks different\nslot for different images (i.e. (a) for the main application and (b) for the\nradio image), boots the main application (from slot (a)) that afterwards starts\nthe radio image by providing an address of the unauthenticated slot ((a)\ninstead of (b))."}],"impacts":[{"capecId":"CAPEC-549","descriptions":[{"lang":"en","value":"CAPEC-549 Local Execution of Code"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-347","description":"CWE-347 Improper verification of cryptographic signature","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-07T07:58:09.190Z","orgId":"30a5e7fb-040d-440a-8cdf-a4a2068ce72e","shortName":"YesWeHack"},"references":[{"url":"https://docs.nordicsemi.com/r/bundle/struct_sa/page/struct/sa.html"}],"source":{"discovery":"UNKNOWN"},"title":"nRF54H20: MCUBoot can be tricked to executing unauthenticated code","x_generator":{"engine":"Vulnogram 1.0.2"}}},"cveMetadata":{"assignerOrgId":"30a5e7fb-040d-440a-8cdf-a4a2068ce72e","assignerShortName":"YesWeHack","cveId":"CVE-2026-14296","datePublished":"2026-09-07T07:58:09.190Z","dateReserved":"2026-07-01T09:51:22.466Z","dateUpdated":"2026-09-07T07:58:09.190Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-07 08:17:11","lastModifiedDate":"2026-09-07 08:17:11","problem_types":["CWE-347","CWE-347 CWE-347 Improper verification of cryptographic signature"],"metrics":{"cvssMetricV31":[{"source":"30a5e7fb-040d-440a-8cdf-a4a2068ce72e","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"14296","Ordinal":"1","Title":"nRF54H20: MCUBoot can be tricked to executing unauthenticated co","CVE":"CVE-2026-14296","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"14296","Ordinal":"1","NoteData":"When using the Direct XIP\nupdate strategy, the main application image starts other cores (i.e. radio\ncore), based on the currently active slot without additional verification. The\nMCUboot in the bare (upstream) configuration assumes that if there is at least\na single slot for each image available, the system is bootable and continues\nthe boot process. This may lead to a situation when MCUboot picks different\nslot for different images (i.e. (a) for the main application and (b) for the\nradio image), boots the main application (from slot (a)) that afterwards starts\nthe radio image by providing an address of the unauthenticated slot ((a)\ninstead of (b)).","Type":"Description","Title":"nRF54H20: MCUBoot can be tricked to executing unauthenticated co"}]}}}