Bluetooth Mesh SDK Vulnerability Leading to Potential Remote Code Execution
CVE-2026-5706

8.9HIGH

Key Information:

Vendor
CVE Published:
27 August 2026

What is CVE-2026-5706?

In versions 6.1.4 and earlier of the Bluetooth Mesh SDK, a security flaw exists wherein malformed extended advertisements can trigger out-of-bounds writes, leading to potential stack corruption and enabling remote code execution. This vulnerability is particularly concerning because it requires the malformed messages to originate from a device that is already a member of the network, thereby increasing the risk of exploitation by an attacker with network access. Only those provisioners that support extended advertisements are at risk.

Affected Version(s)

BT Mesh SDK 0 <= 6.1.4, 9.1.0

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.