A high-severity security flaw has been identified in dealer-installed vehicle anti-theft systems manufactured by Acrisure, according to CISA Advisories. The vulnerability, designated as CVE-2026-18411, affects both the KARR BT and DR-100 firmware platforms. If successfully exploited, an unauthorized actor within physical Bluetooth range can gain partial control over a targeted vehicle, enabling them to unlock doors or activate engine immobilization functions.
The vulnerability is rooted in the system's use of a hard-coded cryptographic key (CWE-321) that is shared across all affected devices. Because this authentication mechanism is identical from unit to unit, an attacker near the vehicle does not need unique user credentials to establish a connection and issue commands. Academic researchers Aaron Schulman, Jerry Yu, Yibo Wei, Sumanth Rao, Mohak Vaswani, Jefferson Chien, Christian Dameff, and Nishant Bhaskar of the University of California, San Diego reported the vulnerability to the Cybersecurity and Infrastructure Security Agency (CISA).
These systems are deployed globally within the transportation systems sector, though the manufacturing firm is headquartered in the United States. To address the security gap, Acrisure Protection Group released a firmware update on July 20, 2026.
Vulnerability Summary
| Parameter | Details |
|---|---|
| Vulnerability ID | CVE-2026-18411 |
| CWE Classification | CWE-321 (Use of Hard-coded Cryptographic Key) |
| CVSS v3.1 Score | 8.1 (High) |
| CVSS v4.0 Score | 7.2 (High) |
| Affected Products | Acrisure KARR BT and DR-100 (Firmware prior to July 20, 2026) |
| Remediation Date | July 20, 2026 |
CISA recommends that vehicle owners and fleet operators verify if their installed security systems are running updated firmware. Users should follow the manufacturer's specific instructions to apply the patch. Additionally, organizations should perform proper risk assessments before deploying defensive measures and ensure connected systems are placed behind firewalls when virtual private networks (VPNs) are used for remote administrative access.
Why It Matters
The discovery of a shared cryptographic key across aftermarket vehicle security systems highlights a significant structural weakness in consumer physical security products. When safety systems rely on uniform authentication secrets, a single compromise can theoretically expose millions of units worldwide to identical attack vectors. As passenger vehicles adopt more wireless control interfaces, accessory suppliers must implement individual key generation mechanisms. Relying on shared secrets means that anti-theft hardware can inadvertently facilitate unauthorized vehicle access instead of preventing it.

Reader Discussion & Insights