Authorization Bypass Vulnerability in Sony XAV-9500ES Devices
CVE-2026-18283
2.4LOW
What is CVE-2026-18283?
The Sony XAV-9500ES exhibits a vulnerability in its udev rules that allows physical attackers to bypass authorization mechanisms. When a malicious USB device is connected to the system, it can exploit the flaw to instantiate restricted USB device types without authentication. This vulnerability poses a significant risk, allowing attackers to manipulate the system by bypassing critical controls.
Affected Version(s)
XAV-9500ES 3.02.00
