SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-5706

HIGH · CVSS 8.9 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Bluetooth Mesh SDK versions 6.1.4 and earlier are vulnerable to out-of-bounds writes caused by malformed extended advertisements, which can lead to stack corruption and potential remote code execution. This vulnerability requires that the malicious messages originate from a device already part of the network, affecting only provisioners that support extended advertisements. Organizations using these SDK versions should prioritize immediate patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-5706
Severity
HIGH
CVSS
8.9
EPSS
0.27%

Original NVD Description

In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted.