CVE-2026-86689: Bransys Eld

Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.

Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.

Affected products

  • Bransys Eld: before 11.00.00 (fixed in 11.00.00); before 1.1.54 (fixed in 1.1.54)

Published 2026-09-18. Last modified 2026-09-18.