Junglewise Threat Intelligence

CVE-2026-49318: Indian Motorcycle Scout Bobber PIN bypass in Infotainment display

CVE-2026-49318 · Severity: low · CVSS 2.4 · Published 2026-05-29

Technologies: Indian Motorcycle Scout Bobber + Tech. Vendors: Indian Motorcycle.

Executive brief

The infotainment system on the 2025 Indian Motorcycle Scout Bobber + Tech contains a flaw that allows the PIN security screen to be bypassed. By interfering with the vehicle's internal communication during startup, an unauthorized person can gain full access to the digital display and its functions without knowing the owner's PIN. This could lead to unauthorized use of the infotainment features and exposure of any stored user data.

Technical details

The vulnerability is caused by an incorrect behavior order and improper check for exceptional conditions during the infotainment system's boot sequence. The system uses the presence of Wireless Control Module (WCM) traffic on the CAN bus as a proxy to determine if an immobilizer is installed; if no traffic is detected during the boot window, the system assumes no immobilizer is present and fails open, skipping the PIN entry screen. An attacker with physical access can exploit this by silencing the WCM (e.g., via a CAN bus-off attack) during startup to present a fully unlocked interface. Specific protocol and timing details are currently withheld by the vendor.

Affected products

  • Indian Motorcycle Scout Bobber + Tech 2025 model year

Timeline

  • 2026-05-29: disclosed: Initial disclosure by ASRG
  • 2026-05-29: advisory: NVD publication date

References