Privilege Escalation Vulnerability in MiracastService by MediaTek
CVE-2026-20516

5.5MEDIUM

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
7 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-20516?

The vulnerability in MiracastService arises from a confused deputy scenario, allowing unauthorized escalation of privileges. Exploitation does not require user interaction, which could result in local denial of service, affecting system stability. It is crucial for users and administrators to apply the relevant patches to mitigate the risk associated with this security flaw.

Affected Version(s)

MediaTek chipset MT5586

MediaTek chipset MT5836

MediaTek chipset MT5838

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.