CVE-2026-20466
Summary
| CVE | CVE-2026-20466 |
|---|---|
| State | PUBLISHED |
| Assigner | MediaTek |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-03 03:16:41 UTC |
| Updated | 2026-08-03 20:17:18 UTC |
| Description | In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: AUTO00845351 (Note: For MT2737) / ALPS11072643 (Note: For MT6880, MT6890, MT6990); Issue ID: MSV-6929. |
Risk And Classification
Primary CVSS: v3.1 6.1 MEDIUM from ADP
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Problem Types: CWE-787 | CWE-787 CWE-787 Out-of-bounds Write
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 6.1 | MEDIUM | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 6.1 | MEDIUM | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
PhysicalAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | MediaTek Inc. | MediaTek Chipset | affected MT2737 | Not specified |
| CNA | MediaTek Inc. | MediaTek Chipset | affected MT6880 | Not specified |
| CNA | MediaTek Inc. | MediaTek Chipset | affected MT6890 | Not specified |
| CNA | MediaTek Inc. | MediaTek Chipset | affected MT6990 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.mediatek.com/product-security-bulletin/August-2026 | [email protected] | www.mediatek.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.