Junglewise Threat Intelligence

CVE-2026-92702: Cocos AI attestation freshness bypass in aTLS AMD SEV-SNP verification

CVE-2026-92702 · Severity: critical · CVSS 9.1 · Published 2026-09-18

Executive brief

Cocos AI is a confidential computing system that runs AI workloads in secure, isolated execution environments. A flaw in its attested TLS (aTLS) verification allows attackers to bypass security checks when no expected reportData value is configured, potentially enabling unauthorized access to or impersonation of the trusted environment. The vulnerability affects versions up to 0.8.2 and is fixed in version 0.9.0.

Technical details

The aTLS AMD SEV-SNP verification path fails to enforce attestation freshness when the expected reportData is nil, empty, or omitted, allowing the verifier to accept stale or unrelated attestation evidence not bound to the current connection. The vulnerability exists in the intra-handshake verification logic where SEV-SNP policy ReportData remains unset, enabling an attacker to supply unverified Evidence from unintended attestation contexts. Mitigation requires providing a non-empty reportData value, which is still properly validated.

Affected products

  • Ultraviolet Cocos AI up to and including 0.8.2

Timeline

  • 2026-09-18: disclosed
  • 2026-03-26: patched: Version 0.9.0 released with fix

References