Junglewise Threat Intelligence

CVE-2026-8676: Silicon Labs Bluetooth LE authentication bypass via bond spoofing

CVE-2026-8676 · Severity: high · CVSS 8.8 · Published 2026-05-26

Vendors: Silicon Labs.

Executive brief

A security flaw in Silicon Labs Bluetooth Low Energy (LE) software allows an attacker within physical proximity to downgrade the security of a wireless connection. By spoofing a trusted device and forcing a new pairing process, an attacker can bypass existing security bonds to gain unauthorized access to the communication. This could lead to the theft of sensitive data or unauthorized control over the affected Bluetooth device.

Technical details

A vulnerability classified as Authentication Bypass by Spoofing (CWE-290) exists in the Silicon Labs Bluetooth LE stack. An attacker within radio range (Adjacent) can trigger a security downgrade by deleting an existing bond and spoofing the identity of a previously bonded device to initiate a new bonding process. This allows the attacker to bypass the protections intended by the original secure bond, potentially leading to full compromise of confidentiality, integrity, and availability of the Bluetooth link. The issue is addressed in Silicon Labs Bluetooth software release 9.0.0.0.

Affected products

  • Silicon Labs Bluetooth LE SDK Prior to 9.0.0.0

Timeline

  • 2026-05-26: disclosed
  • 2026-05-26: advisory

References