# Management Plane Compromise Produces Deterministic Control That Operates Outside Identity Enforcement

- **Artifact ID:** CHQ-P-2026-014
- **Version:** v1.3
- **Status:** ACTIVE
- **Public record:** https://record.cybersecurityhq.com/positions/chq-p-2026-014
- **Machine-record SHA-256:** `986f073962f2222814cdbe3811180c0076ac8ac7d57e9ec00a38168b016bf59f`

## Canonical text

```text
[SECTION] POSITION METADATA
POSITION_ID=CHQ-P-2026-014
VERSION=v1.3
STATUS=ACTIVE
EFFECTIVE=2026-03-24
TITLE=Management Plane Compromise Produces Deterministic Control That Operates Outside Identity Enforcement
DOCTRINE_FAMILY=EXECUTION_GOVERNANCE
ASSUMPTION_INVALIDATED=A-032 (Management plane authority is bounded by identity enforcement at the point of execution)
PRESSURE_CLASS=STRUCTURAL
POSITION_TYPE=STRUCTURAL_OBSERVATION
SIGNAL_COUNT=5
DURABILITY_CLASS=STRUCTURAL
EVIDENCE_STATE=CONFIRMED
VECTOR_COUNT=5
LENS=LENS-001
PATTERN_REGISTER_ID=CHQ-PR-014
SOURCE_SIGNALS=SN-2026-03-19-01, SN-2026-03-05-05, SN-2026-03-16-04, SN-2026-03-19-02, SN-2026-03-24-01
GOVERNING_CONSTRAINT=CHQ-ASC-2026-001
ESG_REFERENCE=CHQ-D-2026-ESG v1.0
REVISION_POLICY=Amendment only

[SECTION] AMENDMENT NOTE
AMENDMENT AMD-001 · JULY 24, 2026 · REINFORCEMENT
Window reinforcement recorded. July 2026 brought confirmed exploitation across the management tier: a collaboration-server zero-day exploited before its patch existed, a remote-access appliance family marking the third independent VPN vendor this season, a broadly deployed network controller line, an eighteen-year-old router flaw newly under active attack, and the identity federation service itself. The condition widened from enterprise appliances into commodity-density equipment. Canonical evidence basis and counts are unchanged; the reinforcement is recorded at the evidence layer.

AMENDMENT AMD-2026-09-22-POSITION-RECORD-CORRECTIVE-WAVE · SEPTEMBER 22, 2026 · POSITION RECORD STANDARD CORRECTION. Publication of CHQ-P-2026-014, canonical field semantics, evidence counts, identifiers, independence wording, and publication integrity corrected under CHQ-RAT-2026-001.

AMENDMENT CHQ-PRS-2026-001-AMD-003 · SEPTEMBER 22, 2026 · GOVERNING CONSTRAINT APPLICABILITY. Governing Constraint was audited under the ratified PRS-06.5 material-applicability test. Default citations were removed, materially load-bearing constraints were retained or added, the prior version and hash were preserved, and the canonical hash was recomputed.

[SECTION] EVIDENCE BASIS
PRIMARY: Primary signals: Five management plane vulnerabilities across four vendors demonstrating unauthenticated remote code execution in enterprise control infrastructure. Each produces system-wide authority without passing through identity enforcement.

SN-2026-03-19-01: Cisco Secure Firewall Management Center CVE-2026-20131 (CVSS 10.0). Unauthenticated RCE via insecure deserialization. Exploited as zero-day by Interlock ransomware group 36 days before public disclosure. Root access to centralized firewall management. Amazon MadPot confirmed exploitation from January 26, 2026.

SN-2026-03-05-05: ConnectWise ScreenConnect CVE-2024-1709. Authentication bypass in remote management platform. Widely exploited for persistent remote access and as alternative pathway during active intrusions.

SN-2026-03-16-04: Handala threat group weaponized Microsoft Intune MDM to wipe approximately 80,000 devices at medical technology manufacturer Stryker. Management tool designed to enforce policy used to execute destructive attack at enterprise scale.

SN-2026-03-19-02: Oracle Identity Manager CVE-2026-21992 (CVSS 9.8). Unauthenticated RCE in the REST WebServices component. Out-of-band emergency patch. Second critical RCE in the same component after CVE-2025-61757 was exploited in the wild. The identity governance system itself is a management plane.

SN-2026-03-24-01: Quest KACE Systems Management Appliance CVE-2025-41080 (CVSS 10.0). Unauthenticated RCE in endpoint management infrastructure. Direct exploitation without identity interaction.
SUPPORTING: SN-2026-03-17-02 (reinforcing): Langflow CVE-2026-33017 (CVSS 9.3)  -  AI workflow platform exploited within 20 hours of advisory. AI platforms function as credential aggregation surfaces with management-plane-equivalent authority over connected services.
SUPPORTING: SN-2026-03-17-03 (reinforcing): AWS Bedrock AgentCore DNS exfiltration  -  delegated authority in AI execution environment. Agent framework inherits enterprise trust and executes with access to connected services. Management-equivalent authority delegated without audit trail.
SUPPORTING: SN-2026-03-20-01 (reinforcing): Trivy supply chain cascade  -  security tool management compromise produced downstream ecosystem infection. The management infrastructure for vulnerability scanning became the attack delivery mechanism. Tool management authority converted to supply chain propagation authority.

[SECTION] AUTHORITY DERIVATION
No constraint derivation applies. This is a standalone Position.

[SECTION] GOVERNING CONSTRAINT
CHQ-ASC-2026-001

[SECTION] SCOPE OF APPLICATION
This Position applies to decisions involving enterprise security architecture, management plane access governance, identity and access management strategy, control plane isolation, and infrastructure recovery planning.

It applies to organizations operating centralized management infrastructure including firewall management centers, endpoint management platforms, identity governance systems, cloud management consoles, and CI/CD pipeline orchestration.

It does not evaluate specific vendors, specific management platform implementations, or specific network segmentation products.

[SECTION] POSITION STATEMENT
Management plane compromise produces deterministic, system-wide effects that can operate outside or override identity enforcement. The management plane is simultaneously the most powerful control surface in the enterprise and the most frequently exposed to unauthenticated exploitation.
The management plane is the highest-leverage impact surface in enterprise environments. Management plane compromise produces deterministic, system-wide effects that can operate outside or override identity enforcement under common enterprise configurations.

Identity compromise produces probabilistic control. It is bounded by scope, privilege level, detection capability, and session constraints. Management plane compromise produces deterministic control. It grants predictable authority over policy, configuration, and infrastructure state across the managed environment.

The distinction is structural. Identity is a policy interpreter. Management planes are policy authors. Compromising the interpreter produces bounded deviation within existing rules. Compromising the author redefines the rules themselves.

Management planes define scopes. Identity systems operate within scopes. When the layer that defines scopes is compromised, identity enforcement becomes contingent on decisions the attacker now controls.

[SECTION] STRUCTURAL OBSERVATION
Together with CHQ-P-2026-009 (Identity Systems Are Becoming the Execution Control Plane), this Position establishes a layered model: identity is the execution interpreter that is gaining primacy at the enforcement layer, while the management plane is the policy authorship layer that defines what identity enforces. These positions are in productive tension, not contradiction. P-009 describes the interpreter gaining primacy. P-014 describes the author layer that the interpreter depends on.

CHQ-P-2026-002 (Verification Collapse Is a Structural Condition): The stress test surfaced an observation upstream of this Position: the true control boundary in enterprise systems is whether authority is independently verified at execution time. P-002 establishes the structural condition. P-014 identifies the specific surface where verification collapse produces the highest-leverage impact.

CHQ-P-2026-006 (No Enterprise Trust Primitive Is Self-Verifying): Management plane compromise succeeds precisely because these systems cannot verify their own integrity. P-006 is a necessary condition for P-014 to hold.

CHQ-P-2026-011 (Tool Presence Cannot Serve as Evidence of Functioning Control): Directly reinforced. Management plane compromise demonstrates that the presence of policy enforcement infrastructure does not prove the integrity of the policies being enforced.

The structural consequence is that the management plane is simultaneously the most powerful control surface in the enterprise and the most frequently exposed to unauthenticated exploitation. Security investment follows attack frequency, which concentrates at the identity and endpoint layers. Impact concentrates at the management plane. This misalignment means the highest-leverage attack surface receives governance attention proportional to its frequency of exploitation, not its consequence of compromise.

[SECTION] ARCHITECTURAL IMPLICATION
The mechanism follows a consistent sequence observed across the evidence set:

Access: Management planes are directly exploitable, frequently without authentication. The dominant vulnerability class in the evidence set is unauthenticated remote code execution, which bypasses the identity layer entirely.

Convergence: Compromise of a single management plane provides authority over all systems it manages. This is not lateral movement. It is inherited authority. The management plane's legitimate function is to propagate policy.

Amplification: The same mechanism that propagates policy propagates compromise. Firewall rules, endpoint configurations, identity assignments, access policies are all modifiable from a single control point. The management plane is a control amplifier by design.

Recovery denial: The management plane typically controls the infrastructure required for remediation. Backup systems, deployment pipelines, monitoring configuration. Compromise of the management plane can eliminate the organization's ability to restore known-good state.

A-032 (Management plane authority is bounded by identity enforcement at the point of execution) is directly invalidated by the dominant vulnerability class in the evidence set. Unauthenticated RCE in Cisco FMC, Oracle OIM, and Quest KACE demonstrates that management plane authority executes without identity mediation. The assumption holds only in environments with execution-time verification (hardware-bound identity, signed requests, attested device context). Under current enterprise conditions, it does not hold. Status: UNDER PRESSURE.

A-020 (Control plane integrity can be verified independently of data plane activity) is directly under pressure. The evidence set demonstrates that management plane compromise produces effects that cannot be distinguished from legitimate policy propagation at the data plane. Control plane integrity is not independently verifiable when the compromise operates through the control plane's own authorized functions.

A-016 (Governance authority boundaries align with execution authority boundaries) is under pressure. Management plane compromise demonstrates that governance authority and execution authority converge at the management layer. An attacker with management plane access has both the authority to define policy and the execution capability to enforce it, collapsing the intended separation.

A-004 (Verification failures can be remediated locally) is under pressure. When the management plane is compromised, the systems required for local remediation are themselves under attacker control. Recovery denial is a structural consequence of management plane compromise, not an optional attacker choice.

[SECTION] EVIDENTIAL RECORD
TITLE=CybersecurityHQ Management Plane Compromise Evidence
DOCKET=CHQ-ED-2026-013
EXHIBITS=NONE
SIGNALS=SN-2026-03-19-01, SN-2026-03-05-05, SN-2026-03-16-04, SN-2026-03-19-02, SN-2026-03-24-01, SN-2026-03-17-02, SN-2026-03-17-03, SN-2026-03-20-01

[SECTION] STRUCTURAL CONSEQUENCE
The structural consequence is that the management plane is simultaneously the most powerful control surface in the enterprise and the most frequently exposed to unauthenticated exploitation. Security investment follows attack frequency, which concentrates at the identity and endpoint layers. Impact concentrates at the management plane. This misalignment means the highest-leverage attack surface receives governance attention proportional to its frequency of exploitation, not its consequence of compromise.

The position holds under the dominant enterprise architecture, where management planes are operationally reachable for orchestration and control. The position's force reduces in architectures where authority is independently verified at execution time: hardware-bound identity, signed requests, attested device context, independent verification of every policy change at the point of enforcement. This is a scope condition, not a falsification.

[SECTION] BOUNDARY OF APPLICATION
Prescriptive network segmentation recommendations
Specific vendor management platform security guidance
Regulatory compliance requirements for control plane governance
Vendor-specific patching or configuration hardening guidance

[SECTION] SUGGESTED CITATION
CybersecurityHQ Position
"Management Plane Compromise Produces Deterministic Control That Operates Outside Identity Enforcement"
CHQ-P-2026-014
Version 1.3
2026-03-24

[SECTION] POSITION STATUS
STATUS=ACTIVE
VERSION=v1.3

[SECTION] RECORD INTEGRITY
SCOPE=PRS-03.1 CANONICAL TEXT (NOT RENDERING)
VERSION=v1.3

[SECTION] DOCTRINAL ALIGNMENT
Standalone Position

[SECTION] REFERENCE CONDITIONS
Authored independently of any subscribing organization
Not tailored to a specific contractual, commercial, or advocacy interest
Subsequent analysis based only on new evidence

[SECTION] LINKED CONDITIONS

[SECTION] LINKED ASSUMPTIONS
```

## Complete structured record

```json
{
  "id": "CHQ-P-2026-014",
  "title": "Management Plane Compromise Produces Deterministic Control That Operates Outside Identity Enforcement",
  "status": "ACTIVE",
  "version": "v1.3",
  "snapshot_date": "2026-03-24",
  "doctrine_family": "EXECUTION_GOVERNANCE",
  "assumption_class": "A-032 (Management plane authority is bounded by identity enforcement at the point of execution)",
  "pressure_class": "STRUCTURAL",
  "position_type": "STRUCTURAL_OBSERVATION",
  "signal_count": 5,
  "pattern_register_id": "CHQ-PR-014",
  "durability_class": "STRUCTURAL",
  "evidence_state": "CONFIRMED",
  "vector_count": 5,
  "lens": "LENS-001",
  "source_signals": [
    "SN-2026-03-19-01",
    "SN-2026-03-05-05",
    "SN-2026-03-16-04",
    "SN-2026-03-19-02",
    "SN-2026-03-24-01"
  ],
  "governing_acj": [
    "CHQ-ASC-2026-001"
  ],
  "evidence_docket": "CHQ-ED-2026-013",
  "evidence_dockets": [
    {
      "docket": "CHQ-ED-2026-013",
      "issue_date": "2026-03-24",
      "position_version": "v1.0"
    },
    {
      "docket": "CHQ-ED-2026-017",
      "issue_date": "2026-05-04",
      "position_version": "v1.0"
    }
  ],
  "prior_evidence_dockets": [
    {
      "docket": "CHQ-ED-2026-017",
      "relationship": "REINFORCEMENT",
      "position_version": "v1.0"
    }
  ],
  "extends_position": null,
  "doctrine_statement": "Management plane compromise produces deterministic, system-wide effects that can operate outside or override identity enforcement. The management plane is simultaneously the most powerful control surface in the enterprise and the most frequently exposed to unauthenticated exploitation.",
  "evidence_basis": {
    "primary": "Primary signals: Five management plane vulnerabilities across four vendors demonstrating unauthenticated remote code execution in enterprise control infrastructure. Each produces system-wide authority without passing through identity enforcement.\n\nSN-2026-03-19-01: Cisco Secure Firewall Management Center CVE-2026-20131 (CVSS 10.0). Unauthenticated RCE via insecure deserialization. Exploited as zero-day by Interlock ransomware group 36 days before public disclosure. Root access to centralized firewall management. Amazon MadPot confirmed exploitation from January 26, 2026.\n\nSN-2026-03-05-05: ConnectWise ScreenConnect CVE-2024-1709. Authentication bypass in remote management platform. Widely exploited for persistent remote access and as alternative pathway during active intrusions.\n\nSN-2026-03-16-04: Handala threat group weaponized Microsoft Intune MDM to wipe approximately 80,000 devices at medical technology manufacturer Stryker. Management tool designed to enforce policy used to execute destructive attack at enterprise scale.\n\nSN-2026-03-19-02: Oracle Identity Manager CVE-2026-21992 (CVSS 9.8). Unauthenticated RCE in the REST WebServices component. Out-of-band emergency patch. Second critical RCE in the same component after CVE-2025-61757 was exploited in the wild. The identity governance system itself is a management plane.\n\nSN-2026-03-24-01: Quest KACE Systems Management Appliance CVE-2025-41080 (CVSS 10.0). Unauthenticated RCE in endpoint management infrastructure. Direct exploitation without identity interaction.",
    "supporting": [
      "SN-2026-03-17-02 (reinforcing): Langflow CVE-2026-33017 (CVSS 9.3)  -  AI workflow platform exploited within 20 hours of advisory. AI platforms function as credential aggregation surfaces with management-plane-equivalent authority over connected services.",
      "SN-2026-03-17-03 (reinforcing): AWS Bedrock AgentCore DNS exfiltration  -  delegated authority in AI execution environment. Agent framework inherits enterprise trust and executes with access to connected services. Management-equivalent authority delegated without audit trail.",
      "SN-2026-03-20-01 (reinforcing): Trivy supply chain cascade  -  security tool management compromise produced downstream ecosystem infection. The management infrastructure for vulnerability scanning became the attack delivery mechanism. Tool management authority converted to supply chain propagation authority."
    ]
  },
  "doctrinal_alignment": [],
  "revision_policy": "Amendment only",
  "esg_reference": "CHQ-D-2026-ESG v1.0",
  "scope": "This Position applies to decisions involving enterprise security architecture, management plane access governance, identity and access management strategy, control plane isolation, and infrastructure recovery planning.\n\nIt applies to organizations operating centralized management infrastructure including firewall management centers, endpoint management platforms, identity governance systems, cloud management consoles, and CI/CD pipeline orchestration.\n\nIt does not evaluate specific vendors, specific management platform implementations, or specific network segmentation products.",
  "position_statement": "The management plane is the highest-leverage impact surface in enterprise environments. Management plane compromise produces deterministic, system-wide effects that can operate outside or override identity enforcement under common enterprise configurations.\n\nIdentity compromise produces probabilistic control. It is bounded by scope, privilege level, detection capability, and session constraints. Management plane compromise produces deterministic control. It grants predictable authority over policy, configuration, and infrastructure state across the managed environment.\n\nThe distinction is structural. Identity is a policy interpreter. Management planes are policy authors. Compromising the interpreter produces bounded deviation within existing rules. Compromising the author redefines the rules themselves.\n\nManagement planes define scopes. Identity systems operate within scopes. When the layer that defines scopes is compromised, identity enforcement becomes contingent on decisions the attacker now controls.",
  "context": "Together with CHQ-P-2026-009 (Identity Systems Are Becoming the Execution Control Plane), this Position establishes a layered model: identity is the execution interpreter that is gaining primacy at the enforcement layer, while the management plane is the policy authorship layer that defines what identity enforces. These positions are in productive tension, not contradiction. P-009 describes the interpreter gaining primacy. P-014 describes the author layer that the interpreter depends on.\n\nCHQ-P-2026-002 (Verification Collapse Is a Structural Condition): The stress test surfaced an observation upstream of this Position: the true control boundary in enterprise systems is whether authority is independently verified at execution time. P-002 establishes the structural condition. P-014 identifies the specific surface where verification collapse produces the highest-leverage impact.\n\nCHQ-P-2026-006 (No Enterprise Trust Primitive Is Self-Verifying): Management plane compromise succeeds precisely because these systems cannot verify their own integrity. P-006 is a necessary condition for P-014 to hold.\n\nCHQ-P-2026-011 (Tool Presence Cannot Serve as Evidence of Functioning Control): Directly reinforced. Management plane compromise demonstrates that the presence of policy enforcement infrastructure does not prove the integrity of the policies being enforced.\n\nThe structural consequence is that the management plane is simultaneously the most powerful control surface in the enterprise and the most frequently exposed to unauthenticated exploitation. Security investment follows attack frequency, which concentrates at the identity and endpoint layers. Impact concentrates at the management plane. This misalignment means the highest-leverage attack surface receives governance attention proportional to its frequency of exploitation, not its consequence of compromise.",
  "governance_condition": "The mechanism follows a consistent sequence observed across the evidence set:\n\nAccess: Management planes are directly exploitable, frequently without authentication. The dominant vulnerability class in the evidence set is unauthenticated remote code execution, which bypasses the identity layer entirely.\n\nConvergence: Compromise of a single management plane provides authority over all systems it manages. This is not lateral movement. It is inherited authority. The management plane's legitimate function is to propagate policy.\n\nAmplification: The same mechanism that propagates policy propagates compromise. Firewall rules, endpoint configurations, identity assignments, access policies are all modifiable from a single control point. The management plane is a control amplifier by design.\n\nRecovery denial: The management plane typically controls the infrastructure required for remediation. Backup systems, deployment pipelines, monitoring configuration. Compromise of the management plane can eliminate the organization's ability to restore known-good state.\n\nA-032 (Management plane authority is bounded by identity enforcement at the point of execution) is directly invalidated by the dominant vulnerability class in the evidence set. Unauthenticated RCE in Cisco FMC, Oracle OIM, and Quest KACE demonstrates that management plane authority executes without identity mediation. The assumption holds only in environments with execution-time verification (hardware-bound identity, signed requests, attested device context). Under current enterprise conditions, it does not hold. Status: UNDER PRESSURE.\n\nA-020 (Control plane integrity can be verified independently of data plane activity) is directly under pressure. The evidence set demonstrates that management plane compromise produces effects that cannot be distinguished from legitimate policy propagation at the data plane. Control plane integrity is not independently verifiable when the compromise operates through the control plane's own authorized functions.\n\nA-016 (Governance authority boundaries align with execution authority boundaries) is under pressure. Management plane compromise demonstrates that governance authority and execution authority converge at the management layer. An attacker with management plane access has both the authority to define policy and the execution capability to enforce it, collapsing the intended separation.\n\nA-004 (Verification failures can be remediated locally) is under pressure. When the management plane is compromised, the systems required for local remediation are themselves under attacker control. Recovery denial is a structural consequence of management plane compromise, not an optional attacker choice.",
  "implications": [
    "Where governance frameworks treat identity enforcement as the primary control surface, the management plane's compromise can produce effects that are indistinguishable from authorized administrative action.",
    "Security investment follows attack frequency, which concentrates at the identity and endpoint layers; impact concentrates at the management plane, producing a structural misalignment between where governance attention is directed and where systemic damage concentrates."
  ],
  "implications_text": "The structural consequence is that the management plane is simultaneously the most powerful control surface in the enterprise and the most frequently exposed to unauthenticated exploitation. Security investment follows attack frequency, which concentrates at the identity and endpoint layers. Impact concentrates at the management plane. This misalignment means the highest-leverage attack surface receives governance attention proportional to its frequency of exploitation, not its consequence of compromise.\n\nThe position holds under the dominant enterprise architecture, where management planes are operationally reachable for orchestration and control. The position's force reduces in architectures where authority is independently verified at execution time: hardware-bound identity, signed requests, attested device context, independent verification of every policy change at the point of enforcement. This is a scope condition, not a falsification.",
  "exclusions": [
    "Prescriptive network segmentation recommendations",
    "Specific vendor management platform security guidance",
    "Regulatory compliance requirements for control plane governance",
    "Vendor-specific patching or configuration hardening guidance"
  ],
  "amendments": "AMD-001; AMD-2026-09-22-POSITION-RECORD-CORRECTIVE-WAVE; CHQ-PRS-2026-001-AMD-003",
  "amendment_note": "AMENDMENT AMD-001 · JULY 24, 2026 · REINFORCEMENT\nWindow reinforcement recorded. July 2026 brought confirmed exploitation across the management tier: a collaboration-server zero-day exploited before its patch existed, a remote-access appliance family marking the third independent VPN vendor this season, a broadly deployed network controller line, an eighteen-year-old router flaw newly under active attack, and the identity federation service itself. The condition widened from enterprise appliances into commodity-density equipment. Canonical evidence basis and counts are unchanged; the reinforcement is recorded at the evidence layer.\n\nAMENDMENT AMD-2026-09-22-POSITION-RECORD-CORRECTIVE-WAVE · SEPTEMBER 22, 2026 · POSITION RECORD STANDARD CORRECTION. Publication of CHQ-P-2026-014, canonical field semantics, evidence counts, identifiers, independence wording, and publication integrity corrected under CHQ-RAT-2026-001.\n\nAMENDMENT CHQ-PRS-2026-001-AMD-003 · SEPTEMBER 22, 2026 · GOVERNING CONSTRAINT APPLICABILITY. Governing Constraint was audited under the ratified PRS-06.5 material-applicability test. Default citations were removed, materially load-bearing constraints were retained or added, the prior version and hash were preserved, and the canonical hash was recomputed.",
  "reference_conditions": [
    "Authored independently of any subscribing organization",
    "Not tailored to a specific contractual, commercial, or advocacy interest",
    "Subsequent analysis based only on new evidence"
  ],
  "evidential_record": {
    "title": "CybersecurityHQ Management Plane Compromise Evidence",
    "docket": "CHQ-ED-2026-013",
    "exhibits": [],
    "signals": [
      "SN-2026-03-19-01",
      "SN-2026-03-05-05",
      "SN-2026-03-16-04",
      "SN-2026-03-19-02",
      "SN-2026-03-24-01",
      "SN-2026-03-17-02",
      "SN-2026-03-17-03",
      "SN-2026-03-20-01"
    ]
  },
  "related_positions": [
    "CHQ-P-2026-002",
    "CHQ-P-2026-006",
    "CHQ-P-2026-009",
    "CHQ-P-2026-011"
  ],
  "pdf_hash": "b4b6a6b8e6ea4963959bdbb832d44a943ea454d55d9b1c1206a340b41725d5b0",
  "prior_hashes": [
    {
      "version": "v1.1",
      "sha256": "6b6220826fd4ca46c757c1c575ae085d9cc3b70ac8d35d8a865c3329f449f2de"
    },
    {
      "version": "v1.2",
      "sha256": "932d6b4fdc724819e2eb2b43991e6c88c674bbdc1f2f325bb989072e4afb8ab9"
    }
  ],
  "canonical_hash": "b4b6a6b8e6ea4963959bdbb832d44a943ea454d55d9b1c1206a340b41725d5b0"
}
```
