SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18283

LOW · CVSS 2.4 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The vulnerability in Sony XAV-9500ES devices allows physical attackers to bypass authorization controls through manipulated USB devices, exploiting flaws in the udev rules. This could enable unauthorized access to restricted device functionalities without requiring authentication. Organizations using these devices should prioritize addressing this vulnerability to mitigate potential physical security risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-18283
Severity
LOW
CVSS
2.4
EPSS
0.23%

Original NVD Description

Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the udev rules. A crafted USB device connected to the system can trigger instantiation of otherwise restricted USB device types. An attacker can leverage this vulnerability to bypass authorization on the system. Was ZDI-CAN-28992.