CVE-2026-10772: Zephyr Project vulnerability
Rejected reason: DUPLICATE This CVE Record has been rejected by the Zephyr Project CNA. CVE-2026-10772 was assigned to a vulnerability already covered by CVE-2026-2411, which was assigned earlier for the same defect: the Bluetooth GATT notify/indicate paths check the permissions of the Characteristic Declaration attribute rather than the Characteristic Value attribute, so the encryption/authentication requirements configured on the value are not enforced. Both identifiers describe the same root cause in subsys/bluetooth/host/gatt.c, fixed by the same commit (c3386f92fe81bd10dc23e6a115e6a80a7d863546). Use CVE-2026-2411 instead.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch c3386f92fe81bd10dc23e6a115e6a80a7d863546
Event History
Frequently Asked Questions
What is CVE-2026-10772?
CVE-2026-10772 is a vulnerability associated with permission checks in the Bluetooth GATT notify/indicate paths in the Zephyr Project.
What is the severity of CVE-2026-10772?
CVE-2026-10772 has a risk rating of 47.
How does the rejection of CVE-2026-10772 affect users?
The rejection of CVE-2026-10772 indicates that its issues are already covered under CVE-2026-2411, so users should refer to the latter for relevant information.
Is there a fix for CVE-2026-10772?
Since CVE-2026-10772 is a duplicate, users should look for fixes related to CVE-2026-2411.
Why was CVE-2026-10772 rejected?
CVE-2026-10772 was rejected because it was found to be a duplicate of CVE-2026-2411, addressing the same vulnerability.