Memory Corruption Vulnerability in ArduinoBLE Bluetooth Low Energy Implementation
CVE-2026-47773

7.2HIGH

Key Information:

Vendor
CVE Published:
11 September 2026

What is CVE-2026-47773?

The ArduinoBLE library, facilitating Bluetooth Low Energy (BLE) connections on select Arduino models, suffers from a memory corruption issue due to insufficient bounds checking in the ATT layer's write request handler. This vulnerability permits a remote, unauthenticated BLE client to corrupt memory associated with the ATTClass global object, adversely impacting the device's functionality. Specifically, devices utilizing ArduinoBLE with one or more characteristics configured with the BLEEncryption property are at risk. Users are advised to update to version 2.0.2 or later to mitigate this vulnerability.

Affected Version(s)

ArduinoBLE < 2.0.2

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.