CVE-2026-67560 HIGH

CVE-2026-67560: Stack-based Buffer Overflow in Bendix EC80 Brake ECU

Vendor Bendix
Product EC80ESP+ J1708
Weakness CWE-121
Published August 27, 2026
Last update August 28, 2026

CVSS base score

7.5/10
Attack vector Adjacent
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting.

Key dates

02Disclosure timeline

August 27, 2026 CVE published
August 28, 2026 Record updated