Security readout for executives and security teams
Plain-English summary
This flaw affects Bluetooth secure pairing. A nearby attacker positioned during a Passkey pairing session may infer the passkey one bit at a time and complete authenticated pairing with the responding device. Risk is highest where Bluetooth pairing occurs in public, shared, or sensitive operational environments.
Executive priority
Treat this as a targeted proximity risk, not an internet-scale emergency. Prioritize environments with sensitive Bluetooth devices, public pairing, medical, industrial, executive, or access-control use cases, and ensure vendor updates and pairing controls are in place.
Technical view
CVE-2020-26558 concerns Bluetooth LE and BR/EDR secure pairing in Core Specification 2.1 through 5.2. The issue involves reflection of the initiator public key and authentication evidence during Passkey authentication, allowing a nearby man-in-the-middle to derive the session Passkey bit by bit.
Likely exposure
Exposure is broad in principle because the source names Bluetooth LE and BR/EDR secure pairing across Core Specification 2.1 through 5.2. Actual organizational exposure depends on device firmware, Bluetooth stack implementation, and whether Passkey pairing is used.
Exploitation context
The source bundle does not show CISA KEV listing or confirmed active exploitation. The attack requires proximity and involvement in the pairing process, which lowers mass exploitation risk but matters for targeted attacks against valuable or poorly supervised devices.
Researcher notes
Evidence supports a protocol-level pairing weakness with downstream vendor advisories from Linux distributions and Intel. The bundle does not provide CVSS, CWEs, exploit-in-the-wild evidence, or a universal fixed version, so remediation must be mapped per implementation and vendor guidance.
Mitigation direction
- Check Bluetooth SIG, CERT, OS, firmware, and chipset vendor guidance for affected implementations.
- Apply relevant Bluetooth stack, kernel, BlueZ, firmware, and vendor security updates.
- Limit Bluetooth pairing to trusted, supervised locations.
- Disable Bluetooth or pairing mode on systems where it is not operationally needed.
- Re-pair sensitive devices after confirmed vendor remediation where vendor guidance recommends it.
Validation and detection
- Inventory devices and systems supporting Bluetooth LE or BR/EDR pairing.
- Identify assets using Bluetooth Core Specification 2.1 through 5.2 behavior where possible.
- Check Linux, BlueZ, chipset, and firmware versions against vendor advisories.
- Review whether Passkey authentication is used for sensitive pairing workflows.
- Confirm operational controls prevent unsupervised pairing in public or shared spaces.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2020-26558 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/reporting-security/CVE reference · x_refsource_MISC
- https://kb.cert.org/vuls/id/799380CVE reference · x_refsource_MISC
- FEDORA-2021-a35b44fd9fCVE reference · vendor-advisory, x_refsource_FEDORA
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00520.htmlCVE reference · x_refsource_CONFIRM
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00517.htmlCVE reference · x_refsource_CONFIRM
- [debian-lts-announce] 20210623 [SECURITY] [DLA 2689-1] linux security updateCVE reference · mailing-list, x_refsource_MLIST
- [debian-lts-announce] 20210623 [SECURITY] [DLA 2690-1] linux-4.19 security updateCVE reference · mailing-list, x_refsource_MLIST
- [debian-lts-announce] 20210626 [SECURITY] [DLA 2692-1] bluez security updateCVE reference · mailing-list, x_refsource_MLIST
- DSA-4951CVE reference · vendor-advisory, x_refsource_DEBIAN
- GLSA-202209-16CVE reference · vendor-advisory, x_refsource_GENTOO
- https://www.kb.cert.org/vuls/id/799380CVE reference
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
