CVE-2026-18411
Acrisure · KARR BT and DR-100
The KARR Security System and SWDS automotive anti-theft systems use shared Bluetooth authentication keys, allowing unauthorized access to vehicle security functions.
Executive summary
Acrisure KARR and DR-100 security systems are vulnerable to unauthorized access due to the use of hard-coded Bluetooth authentication keys.
Vulnerability
The vulnerability stems from the use of hard-coded cryptographic keys for Bluetooth authentication across affected devices. An unauthenticated attacker in proximity to the vehicle can potentially bypass security mechanisms.
Business impact
This vulnerability poses a significant physical and security risk to vehicle owners, as it allows unauthorized parties to interact with anti-theft systems. The CVSS score of 8.1 reflects the high severity of the potential for unauthorized control over automotive security hardware.
Remediation
Immediate Action: Apply the firmware update released by Acrisure on July 20, 2026, by following the instructions provided at the official KARR security portal.
Proactive Monitoring: Ensure that vehicle security systems are updated during routine maintenance and monitor for any abnormal behavior in vehicle security notifications.
Compensating Controls: While physical proximity is required, users should be aware of their surroundings when using Bluetooth-connected vehicle management apps.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Automotive owners and fleet managers should verify their firmware versions and perform the necessary updates provided by Acrisure immediately. This is critical to maintaining the integrity of the vehicle's anti-theft and security systems.