CVE-2026-20587: MediaTek mtee vulnerability
Published Oct 5, 2026
·Updated
In mtee, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9608.
Affected Software
1 affected component
MediaTek mtee
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
mteeto a version that resolves this vulnerability.Patch ALPS11383899
Event History
Oct 5, 2026
CVE Published
via MITRE·01:39 AM
Data Sourced
via MITRE·01:39 AM
DescriptionWeakness
Data Sourced
via NVD·02:16 AM
DescriptionWeakness
Frequently Asked Questions
1
Does exploitation require an end user to take any action?
No. User interaction is not needed for exploitation.
2
What access does an attacker need before they can exploit this issue?
The attacker must already have System privilege. The impact is a further local escalation of privilege.
3
Which identifiers can be used to track remediation for this issue?
The listed patch ID is ALPS11383899, and the issue ID is MSV-9608.