# CVE-2026-47773

## Summary

- **CVE ID:** CVE-2026-47773
- **Severity:** HIGH
- **CVSS Score:** 7.2 (CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-131, CWE-787
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 15, 2026

## Description

ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduino models. Versions prior to 2.0.2 contain a missing bounds check in the ATT layer write request handler that allows a remote, unauthenticated BLE client to corrupt memory in the ATTClass global object. Devices running ArduinoBLE with one or more characteristics configured with the BLEEncryption property are affected. The fix is included starting from the 2.0.2 release.

## Affected Products

- arduino-libraries — ArduinoBLE (< 2.0.2)

## References

- [CNA](https://github.com/arduino-libraries/ArduinoBLE/security/advisories/GHSA-77v6-cw9f-9whg)
- [CNA](https://github.com/arduino-libraries/ArduinoBLE/pull/431/changes/1460e1a68221fca854b7b1e278cab76e763c00e6)
- [CNA](https://github.com/arduino-libraries/ArduinoBLE/releases/tag/2.0.2)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.10%
- **EPSS Percentile:** 1.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-19._