What is CVE-2026-66732?
Sonic 3 A.I.R. contains a vulnerability in the ConnectionManager where source address validation is missing, resolving connections solely by a two-byte local handle. This allows a remote attacker to send spoofed datagrams and potentially hijack connections by bypassing the registered remote address check. Users should update to commit 2492d18 or later.
Azərbaycanca: Sonic 3 A.I.R. oyununda şəbəkə bağlantılarını idarə edən 'ConnectionManager' komponentində mənbə ünvanının yoxlanılmaması zəifliyi aşkarlanıb. Bu, uzaqdan hücum edənə iki baytlıq lokal bağlantı identifikatoru ilə saxta məlumat göndərərək icazəsiz bağlantı ələ keçirməyə imkan verir. İstifadəçilər commit 2492d18 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
In which component of Sonic 3 A.I.R. was the CVE-2026-66732 vulnerability discovered?
This vulnerability was discovered in the 'ConnectionManager' component that handles network connections.
What should users do to protect against CVE-2026-66732?
Users should update to commit 2492d18 or a later version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.