Skip to content
CVE-2026-2411: Bluetooth GATT Characteristic Vulnerability Disclosed

CVE-2026-2411: Bluetooth GATT Characteristic Vulnerability Disclosed

First seen 2 Aug 2026, 20:43 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 3, 2026 at 20:19 UTC
  • CVE-2026-2411 allows unauthorized access to sensitive Bluetooth data.
  • Exploitation requires connecting without pairing or encryption.
  • A fix has been implemented to enforce proper security checks.

CVE-2026-2411 was published on August 1, 2026, detailing a vulnerability in Zephyr's Bluetooth host. The flaw involves a GATT characteristic that improperly handles security permissions, allowing unauthorized access to sensitive data. Attackers can exploit this by connecting without pairing or encryption, enabling notifications that expose protected values. The vulnerability affects applications using the GATT protocol with specific security configurations. The fix involves updating the permission check mechanism to ensure proper security requirements are enforced. No memory safety or availability impacts were reported. The vulnerability is categorized as medium severity.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 48d ago How this analysis works

Timeline

2026-08-01
CVE-2026-2411 published
The vulnerability in Zephyr's Bluetooth host was officially disclosed, detailing security permission mishandling.
nvd.nist.gov
2026-08-02
Vulnerability reported by The Hacker Wire
The Hacker Wire published an article summarizing the details of CVE-2026-2411, highlighting its impact and exploit method.
Thehackerwire

More articles in this cluster (4)

Following this threat?

Track CVE-2026-2411 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed