CVE-2026-87931
A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.6
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
- CWE
- CWE-120, CWE-119
- Published
- 2026-09-09
- Last modified
- 2026-09-10
Affected products
- Behavioral Technology Group Pavlok Behavioral Conditioning Wearable
Weakness type
Related vulnerabilities
- CVE-2026-42808 — An issue was discovered in Bosch Sensortec COINES_SDK versions 2.0 through 2.11....
- CVE-2026-44756 — Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing
- CVE-2026-86166 — Tenda HG10 Boa Web Server formWanRedirect buffer overflow
- CVE-2026-86165 — Tenda HG10 formURL buffer overflow
- CVE-2026-85110 — Tenda HG10 Boa Web Server formWlanSetup buffer overflow
- CVE-2026-85109 — Tenda HG10 Boa Web Server formLogin buffer overflow
- CVE-2026-85031 — TOTOLINK CP450 cstecgi.cgi buffer overflow
- CVE-2026-9625 — RSLinx Classic® - Multiple Vulnerabilities