PT-2026-82772 · Unknown · Bluetooth Mesh Sdk

CVE-2026-5706

·

Published

2026-08-27

·

Updated

2026-08-28

CVSS v4.0

8.9

High

VectorAV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Bluetooth Mesh SDK versions prior to 6.1.5
Description Malformed extended advertisements can trigger out-of-bounds writes, which are memory access operations that occur outside the intended buffer boundaries. This can lead to stack corruption and remote code execution. The issue specifically impacts provisioners that support extended advertisements, and the malicious messages must originate from a device that has already joined the network.
Recommendations Update Bluetooth Mesh SDK to version 6.1.5 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5706

Affected Products

Bluetooth Mesh Sdk