Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Hard‑coded Bluetooth Key (CVE‑2026‑18411) Enables Unauthorized Vehicle Control in Acrisure KARR BT & DR‑100

A CISA advisory details CVE‑2026‑18411, a hard‑coded Bluetooth authentication key affecting Acrisure KARR BT and DR‑100 anti‑theft devices. Exploitation could let attackers unlock doors or immobilize engines, a high‑severity risk that directly challenges SOC 2 access‑control requirements.

LiveThreat™ Intelligence · 📅 August 04, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
cisa.gov

Hard‑coded Bluetooth Key (CVE‑2026‑18411) Enables Unauthorized Vehicle Control in Acrisure KARR BT & DR‑100

What It Is – A hard‑coded cryptographic key is shared across Acrisure KARR BT and DR‑100 anti‑theft devices. An attacker within Bluetooth range can use the key to send forged commands, unlocking doors or immobilizing the engine.

Exploitability – The vulnerability is publicly disclosed (CVE‑2026‑18411) with a CVSS v3 score of 8.1 (High). No public exploit code is known, but the attack requires only proximity and the known key, making exploitation feasible for a motivated adversary.

Affected Products – Acrisure KARR BT firmware < July 20 2026 and Acrisure DR‑100 firmware < July 20 2026 (both classified as “known_affected”).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access Controls – Hard‑coded keys violate logical‑access and authentication requirements (CC6.1, CC6.2). Demonstrating proper key‑management is essential evidence for auditors.
  • Continuous Monitoring – Tracking firmware versions and patch status provides real‑time proof that the organization maintains a defensible security posture.
  • Enterprise Procurement – Buyers in transportation and logistics now demand verifiable SOC 2 controls around IoT/vehicle‑telematics; a lapse can block contracts.

Recommended Actions

  • Deploy Acrisure’s July 20 2026 firmware update to all KARR BT and DR‑100 units immediately.
  • Inventory every deployed device, record firmware levels, and map them to the SOC 2 Access‑Control policy.
  • Implement automated version‑checking (e.g., a CMDB integration) to generate audit‑ready evidence of ongoing compliance.
  • Review and tighten Bluetooth authentication procedures, ensuring no hard‑coded secrets remain in future releases.

Source: CISA Advisory – ICSA‑26‑216‑01

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-216-01 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →