CVE-2026-2411: Bluetooth GATT Characteristic Vulnerability Disclosed

CVE-2026-2411: Bluetooth GATT Characteristic Vulnerability Disclosed

First seen 2 Aug 2026, 20:43 UTC Thehackerwirenvd.nist.govwww.cvedetails.com 88% similarity 59.0

Article Content

Browse articles
ThreatCluster

CVE-2026-2411 was published on August 1, 2026, detailing a vulnerability in Zephyr's Bluetooth host. The flaw involves a GATT characteristic that improperly handles security permissions, allowing unauthorized access to sensitive data. Attackers can exploit this by connecting without pairing or encryption, enabling notifications that expose protected values. The vulnerability affects applications using the GATT protocol with specific security configurations. The fix involves updating the permission check mechanism to ensure proper security requirements are enforced. No memory safety or availability impacts were reported. The vulnerability is categorized as medium severity.

Key Points: • CVE-2026-2411 allows unauthorized access to sensitive Bluetooth data. • Exploitation requires connecting without pairing or encryption. • A fix has been implemented to enforce proper security checks.

ThreatCluster AI How this analysis works

Timeline

2026-08-01
CVE-2026-2411 published
The vulnerability in Zephyr's Bluetooth host was officially disclosed, detailing security permission mishandling.
nvd.nist.gov
2026-08-02
Vulnerability reported by The Hacker Wire
The Hacker Wire published an article summarizing the details of CVE-2026-2411, highlighting its impact and exploit method.
Thehackerwire

Community

Browse all →

Tracked Entities in This Story