CVE-2026-18411

HIGH

Use of hard-coded cryptographic key in Acrisure KARR BT and DR-100

Title source: cna
STIX 2.1

Description

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the vehicle, potentially allowing unauthorized access to vehicle functions, including door unlocking and engine immobilization.

References (1)

Core 1
Core References
Government Resource government-resource
https://www.cisa.gov/news-events/ics-advisories/icsa-26-216-01

Scores

CVSS v3 8.1
EPSS 0.0034
EPSS Percentile 26.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-321
Status published
Products (2)
Acrisure/DR-100 Versions prior to July 20, 2026
Acrisure/KARR BT Versions prior to July 20, 2026
Published Aug 05, 2026
Tracked Since Aug 06, 2026