CVE-2026-20494: Medium severity wifi vulnerability
In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314, BORA00155001, BORA00154907; Issue ID: MSV-7570.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS10960006 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BORA00155314 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BORA00155001 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BORA00154907 - Compensating control
Mitigate the potential local information disclosure by ensuring only trusted code/users have access to the System privilege, since exploitation could occur without user interaction once System privilege is obtained.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20494?
CVE-2026-20494 has a risk rating of 14, indicating a significant vulnerability.
How do I fix CVE-2026-20494?
To fix CVE-2026-20494, apply the provided patches: ALPS10960006, BORA00155314, or BORA00155001.
What are the potential impacts of CVE-2026-20494?
CVE-2026-20494 could lead to local information disclosure if exploited by a malicious actor with System privileges.
Is user interaction required to exploit CVE-2026-20494?
No, user interaction is not needed for the exploitation of CVE-2026-20494.
What component is affected by CVE-2026-20494?
CVE-2026-20494 affects the wifi component due to a missing bounds check.