PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-49322 Indian Motorcycle (Polaris Inc.) CVE debrief

A medium-severity vulnerability in the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the user-set unlock PIN by passively observing a single PIN authentication exchange. The Wireless Control Module (WCM) uses a non-cryptographic operation for its response computation rather than a cryptographic challenge-response mechanism, making the PIN mathematically derivable from one captured exchange. This defeats the motorcycle's primary user-authentication control. The vulnerability was published on 2026-05-29 and carries a CVSS 4.0 score of 4.1 (Medium). The ASRG advisory reference provides the primary technical disclosure, though specific protocol details have been withheld pending vendor remediation. The CVE record status is currently Deferred.

Vendor
Indian Motorcycle (Polaris Inc.)
Product
Scout Bobber + Tech
CVSS
MEDIUM 4.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-29
Original CVE updated
2026-07-21
Advisory published
2026-05-29
Advisory updated
2026-07-21

Who should care

Owners and operators of affected Indian Motorcycle Scout Bobber + Tech 2025 vehicles; fleet managers; automotive security researchers; physical security teams responsible for motorcycle storage and access control; incident response teams tracking connected vehicle threats

Technical summary

The Wireless Control Module (WCM) in the Indian Motorcycle Scout Bobber + Tech 2025 model year implements PIN authentication using a non-cryptographic response computation. An attacker with read access to the in-vehicle network can capture a single PIN authentication exchange between the Infotainment Digital Round display and the WCM, then mathematically derive the user-set unlock PIN from the observed values. This constitutes a passive, adjacent-network authentication bypass against the motorcycle's primary user-authentication control. Specific protocol details are withheld pending vendor remediation.

Defensive priority

medium

Recommended defensive actions

  • Restrict physical and network-layer access to the in-vehicle network to trusted personnel only
  • Monitor for unauthorized diagnostic or network access tools connected to the motorcycle's communication buses
  • Apply vendor firmware or software updates for the Wireless Control Module and Infotainment Digital Round display when available
  • Consider additional physical security controls (e.g., secure parking, tamper-evident hardware) to reduce adjacent-network attack opportunities
  • Review and update threat models for connected vehicle assets to account for passive authentication bypass risks

Evidence notes

The vulnerability description is sourced from the official CVE record and NVD entry. The ASRG reference link provides the originating advisory. Vendor attribution is marked as low-confidence 'Unknown Vendor' with candidate evidence pointing to ASRG as the reference domain; this field is flagged for review.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-49322 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-49322

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-49322 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49322

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://www.asrg.io/security-advisories/cve-2026-49322-indian-scout-infotainment-wcm-weak-authentication

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.