CVE-2026-5768
Last modified
CVE-2026-5768 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations, causing denial-of-service conditions, and fuzzing characteristic values to induce unexpected behavior. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations, causing denial-of-service conditions, and fuzzing characteristic values to induce unexpected behavior. Additionally, the Frontier X mobile application lacks proper BLE device authentication, allowing attackers to impersonate a legitimate Frontier X2 device and connect to the application. By cloning BLE advertisements and exposing expected GATT characteristics, attackers can manipulate activity states and inject fabricated health telemetry such as breathing rate, heart rate, strain, and other health-related data into the mobile application.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-5768?
How severe is CVE-2026-5768?
How do I fix CVE-2026-5768?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-57674Unauthenticated Cross Site Scripting (XSS) in Timetics <= 1.…7.1
- CVE-2026-57675Unauthenticated Cross Site Scripting (XSS) in WP Photo Album…7.1
- CVE-2026-57676Authorization Bypass Through User-Controlled Key vulnerabili…4.3
- CVE-2026-57677Unauthenticated PHP Object Injection in Novalnet Payment Gat…9.8
- CVE-2026-57678Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2026-57679Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions.9.3
- CVE-2026-57680Unauthenticated Insecure Direct Object References (IDOR) in …6.5
- CVE-2026-57681Subscriber Server Side Request Forgery (SSRF) in GeoDirector…6.4
- CVE-2026-57682Unauthenticated Cross Site Scripting (XSS) in Simple Link Di…7.1
- CVE-2026-57683Unauthenticated SQL Injection in WP Fast Total Search <= 1.8…9.3
- CVE-2026-57684Contributor Cross Site Scripting (XSS) in TheFox <= 3.9.70 v…6.5
- CVE-2026-57685Subscriber Broken Access Control in Martfury - WooCommerce M…4.3
Are you affected by CVE-2026-5768?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
