Stack-Based Buffer Overflow in Bendix EC80 Brake ECU
CVE-2026-67560

7.7HIGH

Key Information:

Vendor

Bendix

Vendor
CVE Published:
27 August 2026

What is CVE-2026-67560?

The Bendix EC80 Brake ECU is susceptible to a stack-based buffer overflow, which exposes the system to potential remote code execution threats. An attacker can exploit this vulnerability by sending specially crafted payloads that may lead to system crashes or unauthorized manipulation of the ECU's functionality. This exploitation can compromise critical vehicle functions, such as anti-lock braking system (ABS), steering assist, speedometer readings, and gear shifting, posing significant safety risks.

Affected Version(s)

EC80ESP 2nd CAN Z266494

EC80ESP 4S/4M Z286098

EC80ESP 6S/6M Z266494

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ben Gardiner of NMFTA reported this vulnerability to CISA.
.