Answer in brief
CVE-2026-71396 records a Unknown severity vulnerability in Use of Hard-coded Credentials in Bendix EC80 Brake ECU. The current sources do not mark it as known exploited. The current feed maps Bendix/EC80ESP 2nd CAN (generic), Bendix/EC80ESP+ 2nd CAN (generic), Bendix/EC80ESP 4S/4M (generic), Bendix/EC80ESP 6S/6M (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Bendix/EC80ESP 2nd CAN (generic), Bendix/EC80ESP+ 2nd CAN (generic), Bendix/EC80ESP 4S/4M (generic), Bendix/EC80ESP 6S/6M (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Bendix/EC80ESP 2nd CANgeneric | Z266494 | Not reported |
| Bendix/EC80ESP+ 2nd CANgeneric | Z228999 | Not reported |
| Bendix/EC80ESP 4S/4Mgeneric | Z286098 | Not reported |
| Bendix/EC80ESP 6S/6Mgeneric | Z266494 | Not reported |
| Bendix/EC80ESP+ 6S/6Mgeneric | Z228999 | Not reported |
| Bendix/EC80ESP CAN Gatewaygeneric | Z266494 | Not reported |
| Bendix/EC80ESP+ Integrated TPMSgeneric | Z228999 | Not reported |
| Bendix/EC80ESP+ J1708generic | Z228999 | Not reported |
| Bendix/EC80ESP PLCgeneric | Z266494 | Not reported |
| Bendix/EC80ESP PLCgeneric | Z286098 | Not reported |
| Bendix/EC80ESP+ PLCgeneric | Z228999 | Not reported |
Published upstream
Aug 27, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 27, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 27, 2026
Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable automatic traction control.
Quoted source text, attributed separately from HOL analysis.