Bluetooth Vulnerability in Reachy Mini by Pollen Robotics
CVE-2026-96456

6.3MEDIUM

Key Information:

Vendor
CVE Published:
23 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-96456?

The Reachy Mini's Bluetooth service employs a PIN requirement for connecting devices but fails to properly authenticate individual callers. As a result, an attacker within Bluetooth range can exploit this flaw post-authentication. Once a legitimate device successfully exchanges a PIN, a shared authentication flag allows any nearby device to issue commands without further checks. This vulnerability reveals a significant oversight in maintaining device-specific authentication, enabling attackers to inject commands after leveraging the credentials of legitimate users.

Affected Version(s)

Reachy Mini Linux 0 <= 1.11.0

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Natan Nehorai | JFrog
.