Out-of-Bounds Write Vulnerability in Bendix EC80 Brake ECU
CVE-2026-68967

7.1HIGH

Key Information:

Vendor

Bendix

Vendor
CVE Published:
27 August 2026

What is CVE-2026-68967?

The Bendix EC80 Brake ECU is exposed to an out-of-bounds write vulnerability, which can be exploited by attackers to execute unintended actions, such as crashing the ECU. This may lead to unsafe automotive conditions, and it allows for the potential establishment of arbitrary write primitives, emphasizing the need for immediate attention and security updates to protect against possible exploits.

Affected Version(s)

EC80ESP 2nd CAN Z266494

EC80ESP 4S/4M Z286098

EC80ESP 6S/6M Z266494

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ben Gardiner of NMFTA reported this vulnerability to CISA.
.