CVE-2026-86689
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Summary
Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Bransys | ELD | 0 < 11.00.00 | affected |
| Bransys | ELD | 11.00.00 | unaffected |
| Bransys | ELD | 0 < 1.1.54 | affected |
| Bransys | ELD | 1.1.54 | unaffected |
Weaknesses
- CWE-319: CWE-319 Cleartext transmission of sensitive information
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-01
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-260-01.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.