Buffer Overflow in Bluetooth Continuous Glucose Monitoring Service by Nordic Semiconductor
CVE-2026-14297

8.7HIGH

Key Information:

Vendor
CVE Published:
7 September 2026

What is CVE-2026-14297?

A buffer overflow vulnerability exists in the Bluetooth Continuous Glucose Monitoring Service (CGMS) specifically in the Record Access Control Point (RACP) write handler. This flaw allows an authenticated Bluetooth Low Energy (BLE) peer to overflow a fixed 20-byte static buffer, impacting adjacent BSS memory. The repercussions of exploiting this vulnerability can vary based on the linker-assigned layout of BSS memory in different firmware builds, making potential outcomes unpredictable. Mitigating this issue is essential for maintaining the integrity and security of health-related data transmission.

Affected Version(s)

nRF Connect SDK 2.2.0 <= 3.3.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

https://github.com/V33RU
.