CVE-2026-66732: Origin Validation Error in Eukaryot sonic3air
CVE-2026-66732 is a vulnerability in Eukaryot sonic3air versions up to 26.03.28.0 where the ConnectionManager fails to validate the source address of incoming UDP datagrams. This allows an on-path attacker who can observe cleartext UDP traffic to inject forged packets into established sessions by spoofing the two-byte connection handle. The attacker can terminate sessions, forge channel messages, and send forged request responses without needing IP address spoofing.
AI Analysis
Technical Summary
Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager. Established connections are resolved solely by a two-byte local connection handle without verifying that the datagram source address matches the registered remote address. An attacker on the network path who can observe cleartext UDP traffic can inject arbitrary packets into any established session by forging the two-byte connection identifier. This enables session termination via TerminateConnectionPacket, arbitrary channel message forgery, and forged request responses without requiring IP address spoofing.
Potential Impact
An attacker capable of observing cleartext UDP traffic can inject arbitrary packets into established sessions, potentially terminating sessions or forging messages and responses. This compromises session integrity and reliability, enabling disruption and manipulation of communication without needing IP spoofing.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or workaround is currently documented.
CVE-2026-66732: Origin Validation Error in Eukaryot sonic3air
Description
CVE-2026-66732 is a vulnerability in Eukaryot sonic3air versions up to 26.03.28.0 where the ConnectionManager fails to validate the source address of incoming UDP datagrams. This allows an on-path attacker who can observe cleartext UDP traffic to inject forged packets into established sessions by spoofing the two-byte connection handle. The attacker can terminate sessions, forge channel messages, and send forged request responses without needing IP address spoofing.
CVSS v4.0
Score 8.3high
Affected software
Eukaryot
sonic3air
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager. Established connections are resolved solely by a two-byte local connection handle without verifying that the datagram source address matches the registered remote address. An attacker on the network path who can observe cleartext UDP traffic can inject arbitrary packets into any established session by forging the two-byte connection identifier. This enables session termination via TerminateConnectionPacket, arbitrary channel message forgery, and forged request responses without requiring IP address spoofing.
Potential Impact
An attacker capable of observing cleartext UDP traffic can inject arbitrary packets into established sessions, potentially terminating sessions or forging messages and responses. This compromises session integrity and reliability, enabling disruption and manipulation of communication without needing IP spoofing.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or workaround is currently documented.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-27T16:27:47.647Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a748820bf8831d539bf1b9b
Added to database: 08/06/2026, 13:12:00 UTC
Last enriched: 08/13/2026, 17:14:31 UTC
Last updated: 09/17/2026, 22:01:37 UTC
Views: 60
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.