Junglewise Threat Intelligence

CVE-2026-86520: Bransys ELD hardcoded credentials and cleartext transmission

CVE-2026-86520 · Severity: high · CVSS 7.5 · Published 2026-09-17

Executive brief

Bransys ELD is a fleet management application used in transportation to track vehicle telemetry and operational data. The application contains hardcoded credentials for MQTT and FTP services, and transmits sensitive information in cleartext. An attacker can exploit these weaknesses to gain unauthorized access to real-time vehicle data and firmware across multiple carriers without authentication.

Technical details

The vulnerability stems from three distinct weaknesses in Bransys ELD versions for Android and iOS. CVE-2026-86520 involves hardcoded MQTT credentials shipped with the application, allowing attackers to authenticate to the MQTT broker and read real-time telemetry data for all connected devices without any credentials. CVE-2026-86689 results from cleartext transmission of sensitive information, enabling attackers on the network path to intercept and read all broker communications. CVE-2026-77960 involves hardcoded FTP credentials embedded in the application, permitting unauthenticated FTP server access. All three vulnerabilities require only network access and no user interaction. Bransys has released patches (Android 11.00.00 and later, iOS 1.1.54 and later) that should be installed immediately through the respective app stores.

Affected products

  • Bransys ELD Android <11.00.00
  • Bransys ELD iOS <1.1.54

CVE identifiers

  • CVE-2026-86520
  • CVE-2026-77960
  • CVE-2026-86689

Timeline

  • 2026-09-17: advisory: CISA advisory ICSA-26-260-01 published

References