External risk intelligence

Cocos AI Session Misbinding Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-92701

This vulnerability involves attestation processes for confidential computing and trusted execution environments. While these systems often handle network traffic, they typically operate within specialized, restricted, or backend infrastructure rather than as public-facing services. Public exposure is possible depending on the deployment, but it is not a standard or inherent design requirement.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security flaw in Cocos AI, a system for confidential computing, could allow attackers to misdirect or reuse authentication data, potentially exposing sensitive application information. This vulnerability affects how the system verifies its own security attestations during communication.

  • The system incorrectly validates its own security checks.
  • It could allow unauthorized access to sensitive data.
  • Confirm if this technology is used in your environment.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this by sending specially crafted data during a TLS handshake, bypassing a crucial security check in the attestation process. This could allow them to impersonate a legitimate session, leading to the release of sensitive application data to an unintended party.

  • Requires network access.
  • Triggers during TLS handshake.
  • Risk of session misbinding.

Live Threat

Current exploitation, exposure, and threat context

When supported by Cocos AI's intra-handshake attested TLS (aTLS) Intel TDX verification path, a relying party could accept malformed or reused evidence, potentially releasing application data in an unintended attestation context.

  • Sensitive application data.
  • Weakened attestation context.
  • Unauthorized data release.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world ownership likely falls to the platform or infrastructure teams managing the Cocos AI confidential computing system. The first step is to identify all instances of Cocos AI, determine their network reachability and business criticality, and then locate the accountable owner for each. Remediation planning should then be prioritized based on these findings.

  • Platform/Infrastructure teams own the fix.
  • Verify Cocos AI instances and criticality.
  • Plan remediation based on verified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Cocos AI?

Cocos AI is a software framework designed for confidential computing. It allows developers to run artificial intelligence workloads within hardware-protected areas known as trusted execution environments, which are intended to keep data and computation isolated and secure even from the host system.

What does CWE-346 and CWE-354 mean for CVE-2026-92701?

These codes describe improper validation of integrity and authentication. Specifically, this vulnerability occurs because the system fails to confirm that a security token—a TDX Quote—is fresh and uniquely tied to the current communication session. Because the software does not correctly check the session data, it might accept a replayed or mismatched security confirmation, leading to session misbinding.

How is this vulnerability triggered?

An attacker triggers this by initiating a network connection and interacting with the system's attested TLS handshake. The flaw specifically exists in the verification path for Intel TDX evidence. It is not triggered by standard, non-attested connections or by operations that occur after a successful, verified handshake has already been established.

Do I need to worry if my Cocos AI instance is internal?

According to Halo Surface Signal, this software typically runs in specialized, restricted, or backend infrastructure rather than as a public-facing service. While external network access increases risk, the vulnerability remains relevant for internal environments where lateral movement or unauthorized access by other internal actors is a concern.

When should I update my Cocos AI software?

You should prioritize updating to version 0.9.0 or later as soon as your infrastructure teams confirm the presence of affected instances in your environment. Start by identifying where Cocos AI is deployed and determining its business criticality to schedule the update effectively and mitigate the risk of unauthorized data release.

References