{"id":"CVE-2026-20502","title":"In vdec, there is a possible out of bounds write due to a missing bounds check","summary":"In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A…","severity":"high","cvss":8.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-122"],"vendor":"mediatek","product":"mt2718_firmware","affected":["mt2718_firmware","mt6580_firmware","mt6739_firmware","mt6761_firmware","mt6765_firmware","mt6768_firmware","mt6769_firmware","mt6779_firmware","mt6781_firmware","mt6785_firmware","mt6789_firmware","mt6833_firmware","mt6835_firmware","mt6853_firmware","mt6855_firmware","mt6858_firmware","mt6873_firmware","mt6877_firmware","mt6878_firmware","mt6879_firmware","mt6881_firmware","mt6883_firmware","mt6885_firmware","mt6886_firmware","mt6889_firmware","mt6893_firmware","mt6895_firmware","mt6897_firmware","mt6899_firmware","mt6983_firmware","mt6985_firmware","mt6989_firmware","mt6991_firmware","mt6993_firmware","mt8126_firmware","mt8171_firmware","mt8186_firmware","mt8188_firmware","mt8189_firmware","mt8195_firmware","mt8196_firmware","mt8367_firmware","mt8391_firmware","mt8395_firmware","mt8668_firmware","mt8676_firmware","mt8678_firmware","mt8696_firmware","mt8781_firmware","mt8788e_firmware","mt8792_firmware","mt8799_firmware","mt8910_firmware"],"published":"2026-09-07","updated":"2026-09-09","sourceUpdated":"2026-09-09T02:55:23.187","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20502","references":[{"url":"https://www.mediatek.com/product-security-bulletin/September-2026","label":"security@mediatek.com"}],"tags":["nvd","cve.org"],"epss":0.00128,"epssPercentile":0.02025,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-07T00:00:00+00:00"},"ingestedAt":"2026-09-07T12:10:15.807Z","slug":"CVE-2026-20502","body":"## Overview\n\nIn vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196.\n\n## Affected\n\n- `mt2718_firmware`\n- `mt6580_firmware`\n- `mt6739_firmware`\n- `mt6761_firmware`\n- `mt6765_firmware`\n- `mt6768_firmware`\n- `mt6769_firmware`\n- `mt6779_firmware`\n- `mt6781_firmware`\n- `mt6785_firmware`\n- `mt6789_firmware`\n- `mt6833_firmware`\n- `mt6835_firmware`\n- `mt6853_firmware`\n- `mt6855_firmware`\n- `mt6858_firmware`\n- `mt6873_firmware`\n- `mt6877_firmware`\n- `mt6878_firmware`\n- `mt6879_firmware`\n- `mt6881_firmware`\n- `mt6883_firmware`\n- `mt6885_firmware`\n- `mt6886_firmware`\n- `mt6889_firmware`\n- `mt6893_firmware`\n- `mt6895_firmware`\n- `mt6897_firmware`\n- `mt6899_firmware`\n- `mt6983_firmware`\n- `mt6985_firmware`\n- `mt6989_firmware`\n- `mt6991_firmware`\n- `mt6993_firmware`\n- `mt8126_firmware`\n- `mt8171_firmware`\n- `mt8186_firmware`\n- `mt8188_firmware`\n- `mt8189_firmware`\n- `mt8195_firmware`\n- `mt8196_firmware`\n- `mt8367_firmware`\n- `mt8391_firmware`\n- `mt8395_firmware`\n- `mt8668_firmware`\n- `mt8676_firmware`\n- `mt8678_firmware`\n- `mt8696_firmware`\n- `mt8781_firmware`\n- `mt8788e_firmware`\n- `mt8792_firmware`\n- `mt8799_firmware`\n- `mt8910_firmware`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":46.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}