Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-36028

CVE-2026-36028: Code 27 Companion Hub Auth Bypass Flaw

CVE-2026-36028 is an authentication bypass flaw in Code 27 Companion Hub that allows attackers with physical access to bypass kiosk restrictions via factory reset. This article covers technical details, impact, and mitigation.

Published:

CVE-2026-36028 Overview

CVE-2026-36028 is a protection mechanism failure in the Code 27 Companion Hub. An attacker with physical access to the device can completely bypass kiosk restrictions by triggering a factory reset. The reset workflow does not enforce the kiosk lockdown policy, allowing the device to return to an unrestricted state under attacker control.

The issue affects deployments where the Companion Hub is placed in public or semi-public locations and relies on kiosk mode for policy enforcement. Public exploit material referencing this weakness is hosted in a GitHub Exploit Repository.

Critical Impact

An attacker with brief physical access can neutralize all kiosk restrictions on a Code 27 Companion Hub, gaining full access to the underlying device and any accounts subsequently used on it.

Affected Products

  • Code 27 Companion Hub
  • Deployments configured with kiosk mode restrictions
  • Devices located in physically accessible environments

Discovery Timeline

  • 2026-07-08 - CVE-2026-36028 published to NVD
  • 2026-07-08 - Last updated in NVD database

Technical Details for CVE-2026-36028

Vulnerability Analysis

The vulnerability is a protection mechanism failure in the Code 27 Companion Hub kiosk enforcement layer. Kiosk mode is intended to constrain the device to a narrow set of approved interactions. The factory reset function, however, sits outside the enforcement boundary. An attacker who can reach the reset control clears the kiosk configuration entirely and returns the device to its default, unrestricted state.

This category of flaw is a business logic and configuration design issue rather than a memory safety bug. The kiosk policy is treated as a soft overlay on top of a device that still exposes its recovery primitives. Once the reset completes, no residual controls remain to re-apply the restrictions automatically.

Root Cause

The root cause is that the kiosk restriction layer does not gate or disable the factory reset pathway. Recovery functions remain reachable regardless of the active policy. There is no attestation, tamper evidence, or re-enrollment requirement that would restore restrictions after a reset.

Attack Vector

Exploitation requires physical access to a Companion Hub device. The attacker invokes the factory reset workflow through the exposed hardware or interface path. After the reset completes, the kiosk profile is gone and the device is fully controllable. No credentials, network access, or software vulnerabilities are required. Public proof-of-concept material describing the reset path is available in the referenced exploit repository.

Because no verified code example is published for this entry, refer to the GitHub Exploit Repository for the practical steps documented by external researchers.

Detection Methods for CVE-2026-36028

Indicators of Compromise

  • Companion Hub devices that unexpectedly appear in an unenrolled or default configuration state.
  • Sudden loss of kiosk policy telemetry from a previously managed device.
  • Re-enrollment attempts or first-boot flows originating from devices that were already provisioned.
  • Physical tamper evidence around device enclosures, reset buttons, or service ports.

Detection Strategies

  • Monitor the device management console for policy loss, deregistration, or factory-default check-in events.
  • Correlate physical access logs and video surveillance with device state changes.
  • Alert on gaps in expected heartbeat or telemetry from kiosk-mode endpoints.
  • Track configuration hash or profile identifier changes across the Companion Hub fleet.

Monitoring Recommendations

  • Centralize Companion Hub device logs in a security data lake for longitudinal analysis.
  • Establish a baseline of enrollment state per device and alert on deviation.
  • Review reset and re-provisioning events at least daily for kiosk-deployed devices.

How to Mitigate CVE-2026-36028

Immediate Actions Required

  • Inventory all Code 27 Companion Hub devices and identify those in kiosk deployments.
  • Restrict physical access to devices using locked enclosures, mounts, or tamper-evident seals.
  • Contact the vendor for patch availability and updated hardening guidance from the Companion Security Overview and Code Security Resource.
  • Require automatic re-enrollment and policy reapplication on any device that reports a reset event.

Patch Information

No vendor patch reference is listed in the NVD entry for CVE-2026-36028 at the time of publication. Administrators should track vendor advisories and apply firmware updates as soon as they are released. Until a fix is available, treat physical hardening and monitoring as the primary controls.

Workarounds

  • Place Companion Hub devices in locked kiosk enclosures that block access to the reset interface.
  • Deploy tamper-evident seals and inspect them on a defined schedule.
  • Position devices within line of sight of staff or under active video monitoring.
  • Configure the management platform to quarantine any device that returns to a default state until an administrator re-approves it.
bash
# Configuration example
# Vendor-specific commands are not published in the CVE record.
# Refer to the vendor documentation for exact syntax.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.