Executive brief
Bransys ELD is a fleet management application for electronic logging devices used by transportation carriers. The app transmits sensitive telemetry data over MQTT without encryption, allowing attackers with network access to intercept real-time location and operational data for all connected vehicles. An attacker can read all telemetry from any device connected to the affected MQTT broker without authentication.
Technical details
CVE-2026-86689 affects the MQTT communication channel used by Bransys ELD to transmit device telemetry. The vulnerability involves cleartext transmission of sensitive information over the network without TLS encryption (CWE-319). An unauthenticated, network-based attacker can passively eavesdrop on or actively connect to the MQTT broker to read all sensitive telemetry data from affected devices; no user interaction or authentication is required.
Affected products
- Bransys ELD Android < 11.00.00; iOS < 1.1.54
Timeline
- 2026-09-17: disclosed
- 2026-09-18: advisory: CISA ICS Advisory ICSA-26-260-01 published