CISA Warns of Hard-coded Crypto Key Flaw in Acrisure Vehicle Anti-Theft Systems
CISA advisory ICSA-26-216-01 flags a hard-coded Bluetooth authentication key in Acrisure KARR BT and DR-100 anti-theft systems, allowing nearby attackers to unlock vehicles and disable immobilizers. Firmware updates were released July 20, 2026.
Intelligence analysis by Llama
A CISA advisory highlights a high-severity flaw (CVE-2026-18411, CVSS 8.1) in Acrisure's KARR BT and DR-100 automotive anti-theft systems. A shared hard-coded Bluetooth key lets attackers within range send unauthorized commands, including door unlock and engine immobilizer bypass. Researchers at UC San Diego reported the bug; a patch shipped in July 2026.
Imagine a padlock that comes with the same secret code printed on every lock the factory makes. A thief who learns the code can open any of those locks. That's what happened with Acrisure's car anti-theft boxes — one shared secret let nearby attackers unlock cars and turn off the engine blocker. The company made a fix, and now every car with the old software needs an update.
Analysis
A Lock With the Same Key on Every Door
The vulnerability catalogued as CVE-2026-18411 lives in the authentication layer between a vehicle's KARR BT or DR-100 anti-theft module and the Bluetooth tool a dealer uses to configure it. According to CISA's advisory, those devices share a single hard-coded cryptographic key across every affected unit worldwide. An attacker within Bluetooth range can extract or replay that key and send arbitrary commands to the vehicle, including unlocking doors and, more damagingly, disabling the engine immobilizer that the system is designed to enforce. The flaw carries a CVSS 3.1 base score of 8.1, putting it firmly in the high-severity band.
Discovery by a University Team With ICS Reach
The research was reported by a UC San Diego group — Aaron Schulman, Jerry Yu, Yibo Wei, Sumanth Rao, Mohak Vaswani, Jefferson Chien, Christian Dameff, and Nishant Bhaskar — and forwarded to CISA. The fact that an academic group surfaced this, rather than a vendor security team or a bug bounty, underscores how embedded Bluetooth stacks in physical-security devices often escape the same scrutiny applied to phones and laptops. CISA classified the affected products under the Transportation Systems critical-infrastructure sector and noted worldwide deployment with vendor headquarters in the United States, broadening the policy and supply-chain implications well beyond a single OEM.
Patch Available, but Footprint Matters
Acrisure Protection Group released a firmware update on July 20, 2026, and CISA's advisory links directly to the vendor's installation instructions. At the time of publication, no known public exploitation of CVE-2026-18411 had been reported to CISA, which gives fleet operators and dealer-installed-system integrators a window to push the update before weaponised tooling appears. The harder question is reach: anti-theft modules in this class are often installed by third-party dealers on vehicles that have long since left the OEM's update pipeline, so a CISA bulletin alone is unlikely to drive uniform remediation. The advisory's standard defensive-measures language — network isolation, VPN hygiene, and impact analysis — applies less cleanly here than for a PLC, because the attack surface is a short-range radio link rather than an internet-exposed service.
Key points
- CVE-2026-18411 in Acrisure KARR BT and DR-100 stems from a shared hard-coded Bluetooth authentication key (CWE-321), CVSS 3.1 score 8.1.
- Attackers within Bluetooth range can send unauthorized commands, including door unlock and engine immobilizer bypass.
- Acrisure Protection Group shipped a firmware fix on July 20, 2026; affected versions are any firmware build before that date.
- The flaw was reported by a UC San Diego research team and catalogued by CISA under the Transportation Systems critical-infrastructure sector.
- CISA reports no known public exploitation at the time of advisory publication, giving operators a remediation window.
Because the same hard-coded key exists on every affected device, a single reverse-engineering effort by a criminal or research team instantly compromises the entire installed base. Dealer-installed modules on older vehicles may never receive the July 2026 firmware, leaving a long tail of unpatched units. CISA notes no public exploitation yet, but the low cost of a Bluetooth replay attack makes weaponisation trivial once tooling circulates.


