CVE-2026-8369
MEDIUMImproper Input Validation in OpenThread NAT64 Translator
Title source: cnaDescription
Improper Input Validation in the NAT64 translator in The OpenThread Authors OpenThread before commit 26a882d on all platforms allows an attacker on the adjacent IPv4 network to inject corrupted IPv6 packets into the Thread mesh or bypass security checks via crafted IPv4 packets with options.
References (1)
Core 1
Core References
Scores
CVSS v4
6.0
EPSS
0.0016
EPSS Percentile
5.8%
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-20
Status
published
Products (1)
The OpenThread Authors/OpenThread
commit 26a882d
Published
May 13, 2026
Tracked Since
May 13, 2026