CVE-2026-19292: Bluetooth re-pairing with legitimate device can use lower security level
Published Aug 13, 2026
·Updated
Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below.
Event History
Aug 13, 2026
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-19292?
CVE-2026-19292 has a severity rating of high with a score of 8.8.
2
What vulnerabilities does CVE-2026-19292 introduce?
CVE-2026-19292 exposes devices to brute-force attacks by allowing re-pairing with lower security levels.
3
How does CVE-2026-19292 affect Bluetooth device security?
CVE-2026-19292 makes it easier for attackers to compromise the Long Term Key (LTK) due to reduced security during re-pairing.
4
How can I mitigate the risks associated with CVE-2026-19292?
To mitigate CVE-2026-19292, ensure your Bluetooth devices are updated to the latest firmware to enforce stronger security protocols.
5
What action should I take if I am affected by CVE-2026-19292?
If affected by CVE-2026-19292, consider re-evaluating your Bluetooth pairing procedures and applying all relevant security updates immediately.