CVE-2026-18164

Severity CVSS v4.0:
HIGH
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
13/08/2026
Last modified:
14/08/2026

Description

An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarily manipulate brain stimulation parameters and state.