CVE-2026-4526: Global ZCL command parser missing minimum-length validation in EmberZNet v9.0.2
In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4526?
CVE-2026-4526 has a high severity rating of 7.1 according to the CVSS scoring system.
How do I fix CVE-2026-4526?
To fix CVE-2026-4526, update to EmberZNet version 9.0.3 or later, which addresses the missing minimum-length validation.
What type of vulnerability is CVE-2026-4526?
CVE-2026-4526 is a buffer overflow vulnerability that occurs due to missing minimum-length validation in the global ZCL command parser.
What impact can CVE-2026-4526 have on my network?
CVE-2026-4526 can lead to out-of-bounds reads that may cause the EmberZNet processing framework to terminate unexpectedly.
Who is affected by CVE-2026-4526?
CVE-2026-4526 affects users of EmberZNet v9.0.2 and earlier, particularly those utilizing devices that have joined the network.