Bluetooth Authentication Weakness in KARR Security Systems by KARR
CVE-2026-18411

7.2HIGH

Key Information:

Vendor

Acrisure

Vendor
CVE Published:
5 August 2026

What is CVE-2026-18411?

The KARR Security System and SWDS dealer-installed automotive anti-theft systems exhibit a significant security flaw due to the use of a shared Bluetooth authentication key across multiple devices. This vulnerability allows attackers within Bluetooth range to exploit the weakness and send unauthorized commands to the vehicle. As a result, unauthorized access to vital vehicle functions, such as unlocking doors or manipulating engine systems, could be achieved. Users should remain vigilant and consider security measures to safeguard against potential exploitation.

Affected Version(s)

DR-100 Versions prior to July 20, 2026

KARR BT Versions prior to July 20, 2026

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aaron Schulman, Jerry Yu, Yibo Wei, Sumanth Rao, Mohak Vaswani, Jefferson Chien, Christian Dameff, and Nishant Bhaskar of UC San Diego team discovered this vulnerability.
.