HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Hard‑coded Bluetooth Key (CVE‑2026‑18411) Enables Unauthorized Vehicle Control in Acrisure KARR BT & DR‑100

A CISA advisory details CVE‑2026‑18411, a hard‑coded Bluetooth authentication key affecting Acrisure KARR BT and DR‑100 anti‑theft devices. Exploitation could let attackers unlock doors or immobilize engines, a high‑severity risk that directly challenges SOC 2 access‑control requirements.

LiveThreat™ Intelligence · 📅 August 04, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
cisa.gov

Hard‑coded Bluetooth Key (CVE‑2026‑18411) Enables Unauthorized Vehicle Control in Acrisure KARR BT & DR‑100

What It Is – A hard‑coded cryptographic key is shared across Acrisure KARR BT and DR‑100 anti‑theft devices. An attacker within Bluetooth range can use the key to send forged commands, unlocking doors or immobilizing the engine.

Exploitability – The vulnerability is publicly disclosed (CVE‑2026‑18411) with a CVSS v3 score of 8.1 (High). No public exploit code is known, but the attack requires only proximity and the known key, making exploitation feasible for a motivated adversary.

Affected Products – Acrisure KARR BT firmware < July 20 2026 and Acrisure DR‑100 firmware < July 20 2026 (both classified as “known_affected”).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access Controls – Hard‑coded keys violate logical‑access and authentication requirements (CC6.1, CC6.2). Demonstrating proper key‑management is essential evidence for auditors.
  • Continuous Monitoring – Tracking firmware versions and patch status provides real‑time proof that the organization maintains a defensible security posture.
  • Enterprise Procurement – Buyers in transportation and logistics now demand verifiable SOC 2 controls around IoT/vehicle‑telematics; a lapse can block contracts.

Recommended Actions

  • Deploy Acrisure’s July 20 2026 firmware update to all KARR BT and DR‑100 units immediately.
  • Inventory every deployed device, record firmware levels, and map them to the SOC 2 Access‑Control policy.
  • Implement automated version‑checking (e.g., a CMDB integration) to generate audit‑ready evidence of ongoing compliance.
  • Review and tighten Bluetooth authentication procedures, ensuring no hard‑coded secrets remain in future releases.

Source: CISA Advisory – ICSA‑26‑216‑01

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-216-01

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →