Junglewise Threat Intelligence

CVE-2026-86689: Bransys ELD cleartext transmission of sensitive information in MQTT

CVE-2026-86689 · Severity: medium · CVSS 5.9 · Published 2026-09-18

Technologies: Bransys ELD. Vendors: Bransys.

Executive brief

Bransys ELD is a fleet management application for electronic logging devices used by transportation carriers. The app transmits sensitive telemetry data over MQTT without encryption, allowing attackers with network access to intercept real-time location and operational data for all connected vehicles. An attacker can read all telemetry from any device connected to the affected MQTT broker without authentication.

Technical details

CVE-2026-86689 affects the MQTT communication channel used by Bransys ELD to transmit device telemetry. The vulnerability involves cleartext transmission of sensitive information over the network without TLS encryption (CWE-319). An unauthenticated, network-based attacker can passively eavesdrop on or actively connect to the MQTT broker to read all sensitive telemetry data from affected devices; no user interaction or authentication is required.

Affected products

  • Bransys ELD Android < 11.00.00; iOS < 1.1.54

Timeline

  • 2026-09-17: disclosed
  • 2026-09-18: advisory: CISA ICS Advisory ICSA-26-260-01 published

References

Related threats