SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-56988

MEDIUM · CVSS 6.4 EPSS 0.05% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A race condition in multiple functions of bluetooth_cco.cc can lead to a use-after-free vulnerability, allowing local escalation of privilege to system execution levels. This issue does not require user interaction for exploitation, making it a potential risk for systems utilizing the affected Bluetooth functionality. Organizations that implement Bluetooth services should prioritize addressing this vulnerability to mitigate the risk of unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-56988
Severity
MEDIUM
CVSS
6.4
EPSS
0.05%

Original NVD Description

In multiple functions of bluetooth_cco.cc, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.