CVE-2026-18411

Acrisure · KARR BT and DR-100

The KARR Security System and SWDS automotive anti-theft systems use shared Bluetooth authentication keys, allowing unauthorized access to vehicle security functions.

Executive summary

Acrisure KARR and DR-100 security systems are vulnerable to unauthorized access due to the use of hard-coded Bluetooth authentication keys.

Vulnerability

The vulnerability stems from the use of hard-coded cryptographic keys for Bluetooth authentication across affected devices. An unauthenticated attacker in proximity to the vehicle can potentially bypass security mechanisms.

Business impact

This vulnerability poses a significant physical and security risk to vehicle owners, as it allows unauthorized parties to interact with anti-theft systems. The CVSS score of 8.1 reflects the high severity of the potential for unauthorized control over automotive security hardware.

Remediation

Immediate Action: Apply the firmware update released by Acrisure on July 20, 2026, by following the instructions provided at the official KARR security portal.

Proactive Monitoring: Ensure that vehicle security systems are updated during routine maintenance and monitor for any abnormal behavior in vehicle security notifications.

Compensating Controls: While physical proximity is required, users should be aware of their surroundings when using Bluetooth-connected vehicle management apps.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Automotive owners and fleet managers should verify their firmware versions and perform the necessary updates provided by Acrisure immediately. This is critical to maintaining the integrity of the vehicle's anti-theft and security systems.