# CVE-2026-18796

## Summary

- **CVE ID:** CVE-2026-18796
- **Severity:** MEDIUM
- **CVSS Score:** 6.8 (CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N)
- **CWE:** CWE-1342
- **Published:** Sep 7, 2026
- **Last Modified:** Sep 10, 2026

## Description

Any application that
     uses external QSPI flash for encrypted XIP on nRF5340 and relies on that
     encryption for confidentiality and/or integrity of the externally stored
     code. No specific nRF Connect SDK version is the root cause; the weakness
     is in the on-the-fly decryption scheme.

## Affected Products

- Nordic Semiconductor ASA — nRF5340 (All build codes)

## References

- [CNA](https://docs.nordicsemi.com/r/bundle/struct_sa/page/struct/sa.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.08%
- **EPSS Percentile:** 0.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._