CVE-2026-5706
CVE-2026-5706 is a high-severity vulnerability with a CVSS 4.0 base score of 8.9. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-130.
Key facts
- Severity: High (CVSS 4.0 base score 8.9)
- EPSS exploit prediction: 0% (31st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-130
- Published:
- Last modified:
Description
In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted.
Frequently asked questions
- What is CVE-2026-5706?
- In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted.
- How severe is CVE-2026-5706?
- CVE-2026-5706 has a CVSS 4.0 base score of 8.9, rated high severity.
- Is CVE-2026-5706 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (31st percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-5706?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-5706 published?
- CVE-2026-5706 was published on 2026-08-28 and last updated on 2026-09-08.
References
- https://github.com/SiliconLabs/gecko_sdk/releases
- https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/a45Vm000000Et6HIAS?operationContext=S1
Other CWE-130 vulnerabilities
- CVE-2022-2714 — Critical (CVSS 9.8): Improper Handling of Length Parameter Inconsistency in GitHub repository francoisjacquet/rosariosis prior to 10.0.
- CVE-2026-18397 — Critical (CVSS 9.4): This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a…
- CVE-2026-9054 — Critical (CVSS 9.2): An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel…
- CVE-2026-58096 — High (CVSS 8.8): LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required…
- CVE-2022-1543 — High (CVSS 8.8): Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large…
- CVE-2026-83745 — High (CVSS 8.7): Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in…