CVE-2026-8676 Details
Description
An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond.
A vulnerability exists in the Bluetooth Low Energy (LE) connection management of Silicon Labs devices. An attacker can exploit this issue by deleting an existing bond with a device, spoofing the bonded device's identity, and establishing a new bond. This process effectively downgrades the security of the Bluetooth LE connection.
Users are advised to update to the latest version of the Silicon Labs Bluetooth LE SDK, which includes patches for this vulnerability. The updated SDK can be downloaded through the Silicon Labs Simplicity Studio or via the Silicon Labs GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.silabs.com/068Vm00000p3N9C | [email protected] | |
| https://www.silabs.com/documents/public/release-notes/bt-software-release-notes-9.0.0.0.pdf | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | New CVE Received | [email protected] |