CVE-2026-20686

Severity
5.3MEDIUM
EPSS
0.1%
top 73.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25

Description

This issue was addressed with improved input validation. This issue is fixed in iOS 26.3 and iPadOS 26.3. An app may be able to access sensitive user data.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

NVDapple/ipados< 26.3
CVEListV5apple/ios_and_ipados< 26.3
NVDapple/iphone_os< 26.3

🔴Vulnerability Details

2
GHSA
GHSA-qqh3-3q88-f879: This issue was addressed with improved input validation2026-03-25
CVEList
CVE-2026-20686: This issue was addressed with improved input validation2026-03-25

📋Vendor Advisories

1
Apple
CVE-2026-20686: iOS 26.3 and iPadOS 26.32026-02-11
CVE-2026-20686 (MEDIUM CVSS 5.3) | This issue was addressed with impro | cvebase.io