Junglewise Threat Intelligence

CVE-2026-18164: Flow Neuroscience FL-100 hard-coded credential authentication bypass

CVE-2026-18164 · Severity: high · CVSS 8.1 · Published 2026-08-13

Executive brief

The Flow Neuroscience FL-100 is a brain stimulation device used for therapeutic purposes. An attacker within Bluetooth range can use an undocumented hard-coded credential shared across all units to bypass authentication and arbitrarily modify stimulation parameters and safety settings, potentially causing harm to patients.

Technical details

The vulnerability is a hard-coded credential (CWE-798) embedded in the device firmware that is shared across all FL-100 units. An attacker within Bluetooth range can use this credential to authenticate without authorization, granting them access to modify brain stimulation parameters and override safety limits. No user interaction or prior authentication is required; the vulnerability is triggered purely by proximity. The attack vector is adjacent (Bluetooth range). Firmware updates provided via the Flow app are available to remediate the issue.

Affected products

  • Flow Neuroscience FL-100 before July 2026

Timeline

  • 2026-08-13: disclosed

References