CVE-2026-18796

Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally stored code. No specific nRF Connect SDK version is the root cause; the weakness is in the on-the-fly decryption scheme.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-07 09:17

Updated : 2026-09-09 15:50


NVD link : CVE-2026-18796

Mitre link : CVE-2026-18796

CVE.ORG link : CVE-2026-18796


JSON object : View

Products Affected

No product.

CWE
CWE-1342

Information Exposure through Microarchitectural State after Transient Execution