CVE-2026-8369

MEDIUM

Improper Input Validation in OpenThread NAT64 Translator

Title source: cna
STIX 2.1

Description

Improper Input Validation in the NAT64 translator in The OpenThread Authors OpenThread before commit 26a882d on all platforms allows an attacker on the adjacent IPv4 network to inject corrupted IPv6 packets into the Thread mesh or bypass security checks via crafted IPv4 packets with options.

References (1)

Core 1

Scores

CVSS v4 6.0
EPSS 0.0016
EPSS Percentile 5.8%
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
The OpenThread Authors/OpenThread commit 26a882d
Published May 13, 2026
Tracked Since May 13, 2026