Insufficient API Bounds Checking in NXP NXPNfcRdLib
CVE-2026-87726

3.9LOW

Key Information:

Vendor

Nxp

Vendor
CVE Published:
8 October 2026

What is CVE-2026-87726?

The NXP NXPNfcRdLib contains a vulnerability due to insufficient API bounds checking within the phalFelica module. This flaw can be exploited by an attacker with certain privileges or by untrusted third parties to access unintended memory regions. Exploiting this vulnerability could lead to a potential compromise of confidentiality, integrity, and availability of the system. NXP has addressed this issue in versions 07.18.00 and later, making it crucial for users to update their systems to mitigate risks associated with this vulnerability.

Affected Version(s)

NxpNfcRdLib RC663 < 07.18.00

References

CVSS V3.1

Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.