<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>OpenNHP - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/opennhp/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 21:57:18 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/opennhp/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in OpenNHP via Attestation Verification Manipulation</title><link>https://feed.craftedsignal.io/briefs/2026-09-opennhp-attestation-bypass/</link><pubDate>Wed, 16 Sep 2026 21:57:18 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-opennhp-attestation-bypass/</guid><description>OpenNHP versions up to 1.0.2 contain an authentication bypass vulnerability allowing attackers to force the use of a fallback attestation verifier via malicious input.</description><content:encoded><![CDATA[<p>OpenNHP versions up to 1.0.2 are susceptible to an authentication bypass vulnerability involving the trusted-execution attestation process. The application insecurely selects its attestation verifier based on user-supplied evidence. Specifically, by injecting a 'test_purpose' key into the evidence payload, an attacker can force the application to default to the 'FallbackVerifier' regardless of the actual attestation context. By further providing enrolled measurement values and corresponding serial numbers - which may be obtained from existing allowlists - an attacker can satisfy the conditions required by the fallback logic. This flaw allows unauthorized entities to masquerade as valid devices or services, effectively bypassing the security controls intended to verify the integrity and identity of trusted execution environments. This vulnerability presents a high risk to environments relying on OpenNHP for identity and trust verification.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the complete bypass of attestation-based authentication mechanisms within the OpenNHP framework. This grants unauthorized actors the ability to gain access to restricted network segments or services that rely on these verification checks, potentially leading to unauthorized data access, system manipulation, or further lateral movement within the network.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch OpenNHP to the latest version available that addresses CVE-2026-92792 immediately.</li>
<li>If patching is not immediately feasible, restrict access to the attestation endpoints by implementing strict ingress filtering at the network level to limit the exposure of the management interface.</li>
<li>Audit application logs for anomalous attestation requests that include unusual keys such as 'test_purpose' in the payload.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>authentication-bypass</category><category>attestation</category><category>security-flaw</category></item></channel></rss>