HIGH
CVE-2026-20495
CVSS
7.8
Description
In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00488300; Issue ID: MSV-7296.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
0.1%
Probability of exploitation in next 30 days
1.1th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.