External risk intelligence

Contrast Remote Attestation Relay Attack Defeats Identity Verification

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-100835

The vulnerability affects communication between CLI, Coordinator, and TEE-based components. These operations involve specific architectural roles in secure enclave deployment rather than public-facing services. While network-reachable, this type of infrastructure is typically managed within internal environments or private networks, making public internet exposure uncommon.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects Contrast's remote attestation process, potentially allowing an attacker to impersonate trusted components and bypass identity verification. The issue stems from the system accepting attestation reports without verifying the originating hardware.

  • Remote impersonation attacks are possible.
  • Confirms system trust and identity verification.
  • Verify if your systems are affected.

Attack Path

How an attacker could exploit the issue

An attacker could compromise the integrity of secure communications within Contrast by exploiting a flaw in how it verifies attestation reports from trusted execution environments. This would allow an attacker, who can intercept network traffic and control a trusted execution environment, to relay forged attestation reports. This impersonation could trick Contrast into trusting an unauthorized component, potentially leading to a compromise of its identity verification mechanisms.

  • Network traffic interception is required.
  • Forged attestation reports trigger the vulnerability.
  • Defeats identity verification, impersonating components.

Live Threat

Current exploitation, exposure, and threat context

Remote attestation relay attacks could allow an attacker to impersonate a Contrast Coordinator or workload, bypassing identity verification in Contrast's attested TLS. This is possible when an attacker can intercept network traffic and forge attestation reports, provided they have physical control over at least one Trusted Execution Environment (TEE) machine.

  • System identity verification.
  • Forging attestation reports.
  • Bypassing identity checks.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects Contrast's remote attestation mechanism, impacting the integrity of workload identity verification. Identifying and understanding the specific deployment of Contrast components is the critical first step. This may involve platform or infrastructure teams in coordination with security teams responsible for the attested workloads to determine exposure and risk.

  • Identify and confirm accountable Contrast owners.
  • Verify attestation report reachability and scope.
  • Plan remediation or implement compensating controls.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Contrast and how is it used?

Contrast is software designed for secure enclave deployment using Trusted Execution Environments (TEEs). It helps manage and verify the identity of workloads running within these protected hardware regions. Users deploy it to ensure that the components of their distributed systems, such as the Coordinator and various workloads, are authentic and running in a secure, measured environment before allowing them to participate in sensitive network operations.

What is the weakness in CVE-2026-100835?

This vulnerability is classified as CWE-295, Improper Certificate Validation. In Contrast, the identity verification process failed to bind attestation reports to the specific hardware that generated them. Because the software accepted any validly formatted report regardless of the source, it could not distinguish between a legitimate trusted component and a malicious one, allowing identity verification to be defeated.

How does an attacker trigger this CVE?

An attacker must intercept network traffic between Contrast components and possess a separate TEE machine under their physical control. By forging reports from their own TEE, they can relay this data to impersonate a legitimate Coordinator or workload. Notably, the vulnerability is not triggered if an attacker lacks the ability to capture network communication or cannot produce a valid, correctly signed attestation report from a TEE.

Is my system at risk for this attack?

According to Halo Surface Signal, this vulnerability is unlikely to be exposed on the public internet. Because Contrast involves specialized architectural roles for secure enclave management, it is typically restricted to internal or private networks. However, organizations managing these specific infrastructure components should still evaluate their network configuration and internal access controls to determine if they are reachable.

What should I do if I use Contrast?

First, locate your Contrast deployments and confirm which teams are responsible for the infrastructure. Verify the specific versions currently in use across your environment to determine if they are affected. Coordinate with your security and platform engineering teams to assess the reachability of your attestation reports and prioritize the necessary updates or security controls to secure your workload identity verification.

References