CVE-2026-49316

Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the motorcycle's anti-theft shutdown by forcing the Wireless Control Module (WCM) into the CAN bus-off state. Using a well-known CAN error-frame injection technique against a periodic WCM transmission, the attacker drives the WCM CAN controller's transmit error counter past the bus-off threshold, after which the WCM stops transmitting all messages, including the shutdown command. Peer ECUs do not interpret WCM silence as a security event and continue normal operation, allowing the motorcycle to be operated despite the immobilizer never having been unlocked. Specific protocol details have been withheld pending vendor remediation.
Configurations

No configuration.

History

29 May 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 14:16

Updated : 2026-05-29 15:11


NVD link : CVE-2026-49316

Mitre link : CVE-2026-49316

CVE.ORG link : CVE-2026-49316


JSON object : View

Products Affected

No product.

CWE
CWE-440

Expected Behavior Violation

CWE-693

Protection Mechanism Failure

CWE-754

Improper Check for Unusual or Exceptional Conditions