CVE-2026-49316
Last modified
CVE-2026-49316 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the motorcycle's anti-theft shutdown by forcing the Wireless Control Module (WCM) into the CAN bus-off state. Using a well-known CAN error-frame injection technique against a periodic WCM transmission, the attacker drives the WCM CAN controller's transmit error counter past the bus-off threshold, after which the WCM stops transmitting all messages, including the shutdown command. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the motorcycle's anti-theft shutdown by forcing the Wireless Control Module (WCM) into the CAN bus-off state. Using a well-known CAN error-frame injection technique against a periodic WCM transmission, the attacker drives the WCM CAN controller's transmit error counter past the bus-off threshold, after which the WCM stops transmitting all messages, including the shutdown command. Peer ECUs do not interpret WCM silence as a security event and continue normal operation, allowing the motorcycle to be operated despite the immobilizer never having been unlocked. Specific protocol details have been withheld pending vendor remediation.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-49316?
How severe is CVE-2026-49316?
How do I fix CVE-2026-49316?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-49310Permission control vulnerability in the event notification m…8.6
- CVE-2026-49311Permission control vulnerability in the event notification m…6.2
- CVE-2026-49312Permission control vulnerability in the window module. Impac…4
- CVE-2026-49313Permission control vulnerability in the app lock module. Imp…5.5
- CVE-2026-49314OOB write vulnerability in the rendering and composition mod…7.3
- CVE-2026-49315DoS vulnerability in the input device module. Impact: Succes…7.1
- CVE-2026-49317Incorrect behavior order in the Infotainment / Digital Round…2.4
- CVE-2026-49318Incorrect behavior order in the Infotainment / Digital Round…2.4
- CVE-2026-49319Remote Keyless Entry System (RKES), using the 433 MHz key fo…6.9
- CVE-2026-4932IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW10…4.2
- CVE-2026-49322Weak authentication in the Wireless Control Module (WCM) of …4.3
- CVE-2026-49323Weak authentication between the Wireless Control Module (WCM…4.3
Are you affected by CVE-2026-49316?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
