CVE-2026-20483
Analyzed Analyzed - Analysis Complete

Privilege Escalation in Telephony Component

Vulnerability report for CVE-2026-20483, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-19

Assigner: MediaTek, Inc.

Description

In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-19
Generated
2026-08-23
AI Q&A
2026-08-03
EPSS Evaluated
2026-08-22
NVD
EUVD

Affected Vendors & Products

Showing 35 associated CPEs
Vendor Product Version / Range
mediatek mt8893_firmware *
mediatek mt6739_firmware *
mediatek mt6761_firmware *
mediatek mt6765_firmware *
mediatek mt6768_firmware *
mediatek mt6781_firmware *
mediatek mt6789_firmware *
mediatek mt6833_firmware *
mediatek mt6835_firmware *
mediatek mt6853_firmware *
mediatek mt6855_firmware *
mediatek mt6877_firmware *
mediatek mt6878_firmware *
mediatek mt6879_firmware *
mediatek mt6883_firmware *
mediatek mt6885_firmware *
mediatek mt6886_firmware *
mediatek mt6889_firmware *
mediatek mt6893_firmware *
mediatek mt6895_firmware *
mediatek mt6897_firmware *
mediatek mt6983_firmware *
mediatek mt6985_firmware *
mediatek mt6989_firmware *
mediatek mt6991_firmware *
mediatek mt6993_firmware *
mediatek mt8766_firmware *
mediatek mt8766r_firmware *
mediatek mt8768_firmware *
mediatek mt8775_firmware *
mediatek mt8781_firmware *
mediatek mt8792_firmware *
mediatek mt8796_firmware *
mediatek mt8873_firmware *
mediatek mt8883_firmware *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Telephony allows a local attacker to escalate privileges due to a missing permission check. No additional execution privileges or user interaction are required for exploitation.

Detection Guidance

Detection requires checking for missing permission checks in Telephony components. Review system logs for privilege escalation events or unusual Telephony service activity. No specific commands are provided in the available context.

Impact Analysis

An attacker could exploit this to gain higher privileges on your device, potentially allowing them to access sensitive functions or data without your knowledge.

Compliance Impact

This vulnerability involves a missing permission check in Telephony, enabling local privilege escalation without user interaction or additional privileges. Such flaws could potentially compromise data confidentiality or integrity, which may impact compliance with standards like GDPR or HIPAA if exploited to access or manipulate sensitive information.

Mitigation Strategies

Apply the patch identified as ALPS11087526 to address the missing permission check in Telephony. Ensure the patch is deployed to all affected systems to prevent potential local privilege escalation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20483. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart