CVE-2026-87726
Received Received - Intake

Insufficient API Bounds Checking in NXP NfcRdLib RC663

Vulnerability report for CVE-2026-87726, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: MITRE

Description

Insufficient API bounds checking in phalFelica in NXP NXPNfcRdLib RC663 through 07.14.00_Pub may allow an attacker with privileges or an untrusted third party to access unintended memory regions, potentially leading to limited loss of confidentiality, integrity, and availability. All software versions from 07.18.00 onwards have fixed this problem.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
NXP NxpNfcRdLib RC663

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves insufficient API bounds checking in phalFelica within NXP NXPNfcRdLib RC663 versions up to 07.14.00_Pub. It may allow attackers with privileges or untrusted third parties to access unintended memory regions, potentially causing limited loss of confidentiality, integrity, and availability.

Detection Guidance

Detection requires checking the version of NXP NxpNfcRdLib RC663. Systems running versions before 07.18.00 are vulnerable. Use package managers or file inspection to verify the installed version.

Impact Analysis

The impact includes limited loss of confidentiality, integrity, and availability. Attackers could exploit this to access sensitive data or disrupt system operations, though the extent is constrained by the vulnerability's nature.

Compliance Impact

This vulnerability may lead to limited loss of confidentiality, integrity, and availability due to insufficient API bounds checking. Such issues could potentially result in unauthorized access to sensitive data, which may impact compliance with standards like GDPR (data protection) and HIPAA (healthcare data privacy).

Mitigation Strategies

Update NXP NxpNfcRdLib to version 07.18.00 or later to fix the insufficient API bounds checking issue in phalFelica.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87726. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart