CVE-2026-96456
The Reachy Mini Bluetooth service asks a connecting device for a PIN before it will accept commands. The check protects the session but not the caller, so an attacker in Bluetooth range can ride along on someone else's successful authentication.
The authenticated state is kept in a single shared flag on the service instance rather than per device. BlueZ passes the calling device's identity to the characteristic write handler in the options argument, but WriteValue(self, value, options) in src/reachy_mini/daemon/app/services/bluetooth/bluetooth_service.py ignores options entirely. The handler therefore has no idea which device sent a given write, and it cannot tell the authenticated one from any other.
Leer descripción completaMostrar menos
Once any device completes the PIN exchange, the flag is set and every nearby device can send CMD_ commands until it resets. An attacker simply waits within radio range for a legitimate user to authenticate, then writes commands into the same window. No PIN is ever guessed or brute-forced.
This is the second step of a three-step chain that JFrog documented against the robot. The first is the unrestricted file upload in the media sounds API, tracked as CVE-2026-55419, which places an attacker-controlled script on the filesystem. This issue then provides command access over Bluetooth. The third is the Bluetooth command handler path traversal, tracked as CVE-2026-62661, which runs that script as root.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Puntuación base: 6.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1203Exploitation for Client Executionexecution85 % - Impacto principal
T1078Valid Accountsstealth · persistence · privilege escalation · initial access80 % - Impacto secundario
T1068Exploitation for Privilege Escalationprivilege escalation75 %
Requiere interacción del usuario legítimo (autenticación PIN) para que el atacante aproveche la ventana de sesión compartida. El impacto primario es suplantación de dispositivo autenticado sin credenciales propias.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (2)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-287, CWE-362
Referencias
- https://github.com/pollen-robotics/reachy_mini
- https://github.com/pollen-robotics/reachy_mini/blob/main/src/reachy_mini/daemon/app/services/bluetooth/bluetooth_service.py
- https://github.com/pollen-robotics/reachy_mini/security/advisories/GHSA-993g-hgjh-whmf
- https://www.cve.org/CVERecord?id=CVE-2026-55419
- https://www.cve.org/CVERecord?id=CVE-2026-62661
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-96456",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-96456",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-09-23T13:56:00.359870Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "reefs@jfrog.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.3,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 3.7,
"exploitabilityScore": 2.1
}
]
},
"affected": [
{
"source": "reefs@jfrog.com",
"affectedData": [
{
"repo": "https://github.com/pollen-robotics/reachy_mini",
"vendor": "Pollen Robotics",
"product": "Reachy Mini",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "1.11.0"
}
],
"platforms": [
"Linux"
],
"packageName": "reachy_mini",
"programFiles": [
"src/reachy_mini/daemon/app/services/bluetooth/bluetooth_service.py"
],
"collectionURL": "https://pypi.org",
"defaultStatus": "affected",
"programRoutines": [
{
"name": "WriteValue"
}
]
}
]
}
],
"published": "2026-09-23T11:17:18.843",
"references": [
{
"url": "https://github.com/pollen-robotics/reachy_mini",
"source": "reefs@jfrog.com"
},
{
"url": "https://github.com/pollen-robotics/reachy_mini/blob/main/src/reachy_mini/daemon/app/services/bluetooth/bluetooth_service.py",
"source": "reefs@jfrog.com"
},
{
"url": "https://github.com/pollen-robotics/reachy_mini/security/advisories/GHSA-993g-hgjh-whmf",
"source": "reefs@jfrog.com"
},
{
"url": "https://www.cve.org/CVERecord?id=CVE-2026-55419",
"source": "reefs@jfrog.com"
},
{
"url": "https://www.cve.org/CVERecord?id=CVE-2026-62661",
"source": "reefs@jfrog.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "reefs@jfrog.com",
"description": [
{
"lang": "en",
"value": "CWE-287"
},
{
"lang": "en",
"value": "CWE-362"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Reachy Mini Bluetooth service asks a connecting device for a PIN before it will accept commands. The check protects the session but not the caller, so an attacker in Bluetooth range can ride along on someone else's successful authentication.\n\n\n\nThe authenticated state is kept in a single shared flag on the service instance rather than per device. BlueZ passes the calling device's identity to the characteristic write handler in the options argument, but WriteValue(self, value, options) in src/reachy_mini/daemon/app/services/bluetooth/bluetooth_service.py ignores options entirely. The handler therefore has no idea which device sent a given write, and it cannot tell the authenticated one from any other.\n\n\n\nOnce any device completes the PIN exchange, the flag is set and every nearby device can send CMD_ commands until it resets. An attacker simply waits within radio range for a legitimate user to authenticate, then writes commands into the same window. No PIN is ever guessed or brute-forced.\n\n\n\nThis is the second step of a three-step chain that JFrog documented against the robot. The first is the unrestricted file upload in the media sounds API, tracked as CVE-2026-55419, which places an attacker-controlled script on the filesystem. This issue then provides command access over Bluetooth. The third is the Bluetooth command handler path traversal, tracked as CVE-2026-62661, which runs that script as root."
}
],
"lastModified": "2026-09-23T19:42:02.350",
"sourceIdentifier": "reefs@jfrog.com"
}