LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-31773

CVE-2026-31773 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: May 3, 2026

Linux Kernel Bluetooth SMP - Authentication Bypass

Published: May 1, 2026Updated: May 3, 2026

Overview

Linux kernel Bluetooth SMP contains an authentication bypass caused by incorrect labeling of legacy responder STK authentication state, letting attackers bypass MITM protection, exploit requires Bluetooth pairing process.

Severity & Score

Severity: High
CVSS Score: 8.8

Impact

Attackers can bypass man-in-the-middle protection during Bluetooth pairing, potentially allowing unauthorized device access.

Mitigation

Update to the latest Linux kernel version with the fix applied.

Details

CVE ID
CVE-2026-31773
Severity
High
CVSS Score
8.8
Type
broken_authentication
Status
unconfirmed

CVSS Metrics

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H