CVE-2026-96456
Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-287
Autenticación incorrecta
Fecha de publicación:
23/09/2026
Última modificación:
23/09/2026
Descripción
*** Pendiente de traducción *** The Reachy Mini Bluetooth service asks a connecting device for a PIN before it will accept commands. The check protects the session but not the caller, so an attacker in Bluetooth range can ride along on someone else&#39;s successful authentication.<br />
<br />
<br />
<br />
The authenticated state is kept in a single shared flag on the service instance rather than per device. BlueZ passes the calling device&#39;s identity to the characteristic write handler in the options argument, but WriteValue(self, value, options) in src/reachy_mini/daemon/app/services/bluetooth/bluetooth_service.py ignores options entirely. The handler therefore has no idea which device sent a given write, and it cannot tell the authenticated one from any other.<br />
<br />
<br />
<br />
Once any device completes the PIN exchange, the flag is set and every nearby device can send CMD_ commands until it resets. An attacker simply waits within radio range for a legitimate user to authenticate, then writes commands into the same window. No PIN is ever guessed or brute-forced.<br />
<br />
<br />
<br />
This is the second step of a three-step chain that JFrog documented against the robot. The first is the unrestricted file upload in the media sounds API, tracked as CVE-2026-55419, which places an attacker-controlled script on the filesystem. This issue then provides command access over Bluetooth. The third is the Bluetooth command handler path traversal, tracked as CVE-2026-62661, which runs that script as root.
Impacto
Puntuación base 3.x
6.30
Gravedad 3.x
MEDIA
Referencias a soluciones, herramientas e información
- https://github.com/pollen-robotics/reachy_mini
- https://github.com/pollen-robotics/reachy_mini/blob/main/src/reachy_mini/daemon/app/services/bluetooth/bluetooth_service.py
- https://github.com/pollen-robotics/reachy_mini/security/advisories/GHSA-993g-hgjh-whmf
- https://www.cve.org/CVERecord?id=CVE-2026-55419
- https://www.cve.org/CVERecord?id=CVE-2026-62661


