OCTOBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-10772

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The vulnerability affects the Bluetooth GATT implementation, where permission checks are incorrectly applied to the Characteristic Declaration attribute instead of the Characteristic Value attribute. This oversight allows unauthorized access to sensitive data, as the encryption and authentication requirements for the value are not enforced. Organizations utilizing Bluetooth GATT in their products should prioritize addressing this issue to mitigate potential data exposure risks.

CVE
CVE-2026-10772
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A

Original NVD Description

Rejected reason: ** DUPLICATE ** This CVE Record has been rejected by the Zephyr Project CNA. CVE-2026-10772 was assigned to a vulnerability already covered by CVE-2026-2411, which was assigned earlier for the same defect: the Bluetooth GATT notify/indicate paths check the permissions of the Characteristic Declaration attribute rather than the Characteristic Value attribute, so the encryption/authentication requirements configured on the value are not enforced. Both identifiers describe the same root cause in subsys/bluetooth/host/gatt.c, fixed by the same commit (c3386f92fe81bd10dc23e6a115e6a80a7d863546). Use CVE-2026-2411 instead.