CyberRota Analysis
AI-GeneratedThe vulnerability affects the Bluetooth GATT implementation, where permission checks are incorrectly applied to the Characteristic Declaration attribute instead of the Characteristic Value attribute. This oversight allows unauthorized access to sensitive data, as the encryption and authentication requirements for the value are not enforced. Organizations utilizing Bluetooth GATT in their products should prioritize addressing this issue to mitigate potential data exposure risks.
Original NVD Description
Rejected reason: ** DUPLICATE ** This CVE Record has been rejected by the Zephyr Project CNA. CVE-2026-10772 was assigned to a vulnerability already covered by CVE-2026-2411, which was assigned earlier for the same defect: the Bluetooth GATT notify/indicate paths check the permissions of the Characteristic Declaration attribute rather than the Characteristic Value attribute, so the encryption/authentication requirements configured on the value are not enforced. Both identifiers describe the same root cause in subsys/bluetooth/host/gatt.c, fixed by the same commit (c3386f92fe81bd10dc23e6a115e6a80a7d863546). Use CVE-2026-2411 instead.