CVE-2026-4272
Last modified
CVE-2026-4272 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Missing Authentication for Critical Function vulnerability in Honeywell Handheld Scanners allows Authentication Abuse.This issue affects Handheld Scanners: from C1 Base(Ingenic x1000) before GK000432BAA, from D1 Base(Ingenic x1600) before HE000085BAA, from A1/B1 Base(IMX25) before BK000763BAA_BK000765BAA_CU000101BAA. This vulnerability could allow a remote attacker within Bluetooth range of the scanner's base station has the capability to remotely execute system commands on the host connected to the base station without authentication. This issue has been assigned CVE-2026-4272 https://nvd.nist.gov/vuln/detail/CVE-2026-4272 and rated with a severity of High. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
Missing Authentication for Critical Function vulnerability in Honeywell Handheld Scanners allows Authentication Abuse.This issue affects Handheld Scanners: from C1 Base(Ingenic x1000) before GK000432BAA, from D1 Base(Ingenic x1600) before HE000085BAA, from A1/B1 Base(IMX25) before BK000763BAA_BK000765BAA_CU000101BAA. This vulnerability could allow a remote attacker within Bluetooth range of the scanner's base station has the capability to remotely execute system commands on the host connected to the base station without authentication. This issue has been assigned CVE-2026-4272 https://nvd.nist.gov/vuln/detail/CVE-2026-4272 and rated with a severity of High. Honeywell strongly recommends that users upgrade to the latest version identified to resolve the vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Honeywell | Barcode Scanners | >= C1 Base(Ingenic x1000), < GK000432BAA; >= D1 Base(Ingenic x1600), < HE000085BAA; >= A1/B1 Base(IMX25), < BK000763BAA_BK000765BAA_CU000101BAA |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-4272?
How severe is CVE-2026-4272?
How do I fix CVE-2026-4272?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-42686Subscriber Cross Site Scripting (XSS) in EventPrime <= 4.3.2…7.1
- CVE-2026-42687Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.…8.1
- CVE-2026-42688Subscriber Cross Site Scripting (XSS) in Modula Image Galler…6.5
- CVE-2026-4269A missing S3 ownership verification in the Bedrock AgentCore…7.5
- CVE-2026-4270Improper Protection of Alternate Path exists in the no-acces…6.8
- CVE-2026-4271A flaw was found in libsoup, a library for handling HTTP req…7.5
- CVE-2026-42725Authorization Bypass Through User-Controlled Key vulnerabili…6.5
- CVE-2026-42726Missing Authorization vulnerability in Strategy11 Team AWP C…6.5
- CVE-2026-42727Improper Neutralization of Special Elements used in an SQL C…9.3
- CVE-2026-42728Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2026-42729Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2026-4273Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fa…4.3
Are you affected by CVE-2026-4272?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
