CVE-2026-45328
A critical flaw in Espressif's ESP‑IDF 5.5.4 and 6.0 allows attackers to read and write arbitrary memory and execute code with the same privileges as the application. The bug is in the secure‑service wrappers that forward calls to TEE‑protected peripherals. It can be fixed by upgrading to the patched releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Developers using Espressif ESP‑IDF 5.5.4 or 6.0 to build IoT firmware for ESP32‑based devices.
Real-world impact
An attacker who can influence the device can read sensitive data, tamper with firmware, or take full control of the device, potentially compromising connected systems.
Why this severity
The CVSS score of 9.3 reflects local access with no authentication, no user interaction, and full confidentiality, integrity, and availability impact. The vector shows that an attacker can exploit the flaw from the same device, with low complexity, and gain complete control.
What to do about it
- 01Upgrade ESP-IDF to version 5.5.5 or later.
- 02Upgrade ESP-IDF to version 6.0.1 or later.
NVD-referenced vendor advisory
Timeline
- Jun 10, 2026 · Jun 10, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 24, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/espressif/esp-idf/commit/14…patch
- github.com/espressif/esp-idf/commit/44…patch
- github.com/espressif/esp-idf/commit/76…patch
- github.com/espressif/esp-idf/commit/78…patch
- github.com/espressif/esp-idf/commit/af…patch
- github.com/espressif/esp-idf/commit/ee…patch
- github.com/espressif/esp-idf/security/…mitigationpatchvendor advisory