Junglewise Threat Intelligence

CVE-2026-92701: Cocos AI session-misbinding in Intel TDX attested TLS verifier

CVE-2026-92701 · Severity: critical · CVSS 9.1 · Published 2026-09-18

Executive brief

Cocos AI is a confidential computing system that runs AI workloads in trusted execution environments using attested TLS (aTLS) to verify secure connections. In versions up to 0.8.2, the Intel TDX verification path fails to validate session freshness, allowing an attacker to reuse or forge attestation evidence and trick the system into accepting sessions bound to unintended contexts, potentially exposing sensitive application data.

Technical details

The vulnerability is a session-misbinding flaw in the intra-handshake aTLS implementation for Intel TDX. The verifier fails to copy the expected current-session REPORT_DATA freshness value into the TDX quote-body policy before validation, allowing structurally valid QuoteV4 evidence with mismatched or reused reportData to be accepted. An attacker with network access can exploit this during the TLS handshake to bind the session to a different attestation context and access application data intended for another session.

Affected products

  • Ultraviolet RS Cocos AI up to and including 0.8.2

Timeline

  • 2026-08-16: disclosed
  • 2026-03-27: patched: Fixed in version 0.9.0 with migration to post-handshake attestation
  • 2026-09-18: advisory

References