CVE-2026-46728HIGH 8.2EPSS p2.6%

CVE-2026-46728CVE-2026-46728

Description

Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.

Scoring

CVSS 3.18.2 (HIGH)
VectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS0.13% probability of exploitation · percentile 2.6% · 2026-06-19T12:03:05Z
Published2026-05-16
Last modified2026-05-18

Underlying weaknesses· 1

CWE-346

References

  1. https://github.com/barebox/barebox/security/advisories/GHSA-3fvj-q26p-j6h4
  2. https://github.com/u-boot/u-boot/commit/2092322b31cc8b1f8c9e2e238d1043ae0637b241

1

TypeTargetConfidenceTier
WeaknessOrigin Validation Errorcwe-3460%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-33243
CVE
CVE-2026-24088
CVE
CVE-2026-24090
CVE
CVE-2026-24089
CVE
CVE-2026-24091
CVE
CVE-2026-24087
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.