AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-18164

HIGH · CVSS 8.1 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

A hard-coded credential present in unspecified devices allows attackers within Bluetooth range to bypass authentication, enabling them to manipulate brain stimulation parameters and states. This vulnerability poses a significant risk to the safety and integrity of medical devices, making it critical for manufacturers and healthcare organizations to prioritize remediation efforts. Immediate action is necessary to protect patients and ensure compliance with security standards.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-18164
Severity
HIGH
CVSS
8.1
EPSS
0.23%

Original NVD Description

An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarily manipulate brain stimulation parameters and state.