---
id: CVE-2026-18411
title: >-
  The KARR Security System and SWDS dealer-installed automotive anti-theft
  systems use a shared Bluetooth authentication key across affected devices
summary: >-
  The KARR Security System and SWDS dealer-installed automotive anti-theft
  systems use a shared Bluetooth authentication key across affected devices. An
  attacker within Bluetooth range can leverage this weakness to issue
  unauthorized comma…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-321
published: '2026-08-05'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:30:43.093'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18411'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-216-01'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.00335
epssPercentile: 0.24322
ingestedAt: '2026-09-08T20:10:03.156Z'
---

## Overview

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the vehicle, potentially allowing unauthorized access to vehicle functions, including door unlocking and engine immobilization.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
