CVE-2026-5706: Buffer overflow in Bluetooth Mesh SDK when handling extended advertisements
Published Aug 27, 2026
·Updated
In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted.
Affected Software
1 affected component
Bluetooth Mesh SDK Bluetooth Mesh SDK<=6.1.4
Event History
Aug 27, 2026
CVE Published
via MITRE·10:13 PM
Data Sourced
via MITRE·10:13 PM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments are exposed?
Only provisioners that support extended advertisements may be impacted. The issue affects Bluetooth Mesh SDK versions 6.1.4 and earlier.
2
Does an attacker need access to the Bluetooth Mesh network?
Yes. The malformed extended advertisements must originate from a device that has already joined the network.
3
What is the potential impact of successful exploitation?
Malformed extended advertisements can cause out-of-bounds writes, leading to stack corruption and remote code execution.