---
id: CVE-2026-87726
title: >-
  Insufficient API bounds checking in phalFelica in NXP NXPNfcRdLib RC663
  through 07.14.00_Pub may allow an attacker with privileges or an untrusted
  third party to access unintended memory regions, potentially leading to
  limited loss of co…
summary: >-
  Insufficient API bounds checking in phalFelica in NXP NXPNfcRdLib RC663
  through 07.14.00_Pub may allow an attacker with privileges or an untrusted
  third party to access unintended memory regions, potentially leading to
  limited loss of co…
severity: low
cvss: 3.9
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-787
vendor: NXP
product: NxpNfcRdLib
affected:
  - NxpNfcRdLib >= RC663 < 07.18.00
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T02:16:54.713'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87726'
references:
  - url: >-
      https://community.nxp.com/t5/Other-NXP-Products/NXPNfcRdLib-vulnerability-in-module-phalFelica-CVE-2026-87726/m-p/2414096#M33365
    label: cve@mitre.org
  - url: 'https://www.nxp.com/support/support/product-security-vulnerability:PSIRT'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-08T03:03:35.539Z'
---

## Overview

Insufficient API bounds checking in phalFelica in NXP NXPNfcRdLib RC663 through 07.14.00_Pub may allow an attacker with privileges or an untrusted third party to access unintended memory regions, potentially leading to limited loss of confidentiality, integrity, and availability. All software versions from 07.18.00 onwards have fixed this problem.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
