CVE-2020-26559
Linux Ubuntu vulnerability analysis and mitigation

Overview

The Bluetooth Mesh Profile AuthValue leak (CVE-2020-26559) is a security vulnerability discovered in Bluetooth Mesh Profile versions 1.0 and 1.0.1. The vulnerability was disclosed on May 24, 2021, affecting the provisioning process in Bluetooth Mesh networks. This flaw allows a nearby device participating in the provisioning protocol to identify the AuthValue used, given the Provisioner's public key, confirmation number, and nonce provided by the provisioning device (NIST NVD, CERT Advisory).

Technical details

The vulnerability has a CVSS v3.1 Base Score of 8.8 (HIGH) with the vector string CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Even when using a randomly generated AuthValue with full 128-bits of entropy, an attacker can compute the AuthValue directly by acquiring the Provisioner's public key, provisioning confirmation value, and provisioning random value, and providing its public key for use in the provisioning procedure (NIST NVD).

Impact

The vulnerability could allow an attacker to compute the AuthValue and authenticate to both the Provisioner and provisioned devices. This enables unauthorized access to the provisioning process without requiring brute-force of the AuthValue, potentially compromising the security of the entire mesh network (CERT Advisory).

Exploitability

The vulnerability can be exploited by a nearby attacker who can participate in the provisioning protocol. The attack does not require brute-forcing the AuthValue, making it a practical threat for devices within wireless range. The exploit allows an attacker to complete provisioning without knowledge of the AuthValue (Hacker News).

Mitigation and workarounds

The Bluetooth Special Interest Group (SIG) recommends that potentially vulnerable mesh provisioners use an out-of-band mechanism to exchange the public keys. Users should ensure they have installed the latest recommended updates from device and operating system manufacturers (Bluetooth SIG).

Community reactions

Several major vendors were identified as affected by this vulnerability, including Android Open Source Project (AOSP), Cisco, Cradlepoint, Intel, and Microchip Technology. AOSP and Cisco acknowledged the vulnerability and began working on security updates to address the issue (GBHackers).

Additional resources


SourceThis report was generated using AI

Related Linux Ubuntu vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-42170HIGH7.8
  • Linux Debian logoLinux Debian
  • gimp:2.8::pygtk2-doc
NoYesAug 08, 2026
CVE-2026-56818MEDIUM6.5
  • Java logoJava
  • netty-tcnative
NoYesAug 07, 2026
CVE-2026-61477LOW2.3
  • Linux Debian logoLinux Debian
  • libvirt-daemon-driver-storage-disk
NoNoAug 07, 2026
CVE-2026-16742NONEN/A
  • Linux Ubuntu logoLinux Ubuntu
  • systemd
NoYesAug 10, 2026
CVE-2026-15059NONEN/A
  • Linux Ubuntu logoLinux Ubuntu
  • systemd
NoYesAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management