CVE-2026-18283: Sony Xav-9500es

Low severity, CVSS 2.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the udev rules. A crafted USB device connected to the system can trigger instantiation of otherwise restricted USB device types. An attacker can leverage this vulnerability to bypass authorization on the system. Was ZDI-CAN-28992.

Affected products

  • Sony Xav-9500es: version 3.02.00 only

Published 2026-08-20. Last modified 2026-08-31.