---
id: CVE-2026-87931
title: >-
  A vulnerability has been found in Behavioral Technology Group Pavlok
  Behavioral Conditioning Wearable up to 20260707
summary: >-
  A vulnerability has been found in Behavioral Technology Group Pavlok
  Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown
  function of the component Apple Notification Center Service Event Handler. The
  manipulation lead…
severity: critical
cvss: 9.6
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-120
vendor: Behavioral Technology Group
product: Pavlok Behavioral Conditioning Wearable
affected:
  - pavlok_behavioral_conditioning_wearable 20260707
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T14:39:13.757'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87931'
references:
  - url: 'https://doi.org/10.13140/RG.2.2.35058.88009'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-87931'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/881885'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/401814'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/401814/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-10T13:38:24.945879Z'
ingestedAt: '2026-09-14T08:41:22.830Z'
epss: 0.00602
epssPercentile: 0.46583
---

## Overview

A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
