MEDIUM 6.8

CVE-2026-36028: Code 27 Companion Hub Factory Reset Authentication Bypass

CVE-2026-36028 is a protection mechanism failure in the Code 27 Companion Hub that allows an attacker with physical access to the device to completely bypass kiosk restrictions by performing a factory reset. The vulnerability requires no authentication or user interaction and exposes high-value information and system integrity. The risk is primarily environmental—it only affects devices where physical access can be obtained and where kiosk restrictions are relied upon for security.

Source data · NVD / CISA · public domain

CVSS
3.1 · 6.8 MEDIUM · CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-288
Affected products
0 configuration(s)
Published / Modified
2026-07-08 / 2026-07-09

NVD description (verbatim)

A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass kiosk restrictions via a factory reset

3 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

The Code 27 Companion Hub contains an authentication or access control weakness (CWE-288) in its factory reset functionality. The protection mechanisms that enforce kiosk mode restrictions are not properly validated or protected during the reset process, allowing an attacker with physical access to restore the device to factory defaults without authentication. Once reset, the attacker can bypass all kiosk-mode protections, gaining full access to the system with the privileges of the device. The CVSS score of 6.8 (MEDIUM) reflects that while the impact is high across confidentiality, integrity, and availability, the attack vector is physical-only with low complexity.

Business impact

Organizations deploying Code 27 Companion Hub devices in shared, public, or semi-supervised environments face operational and security risks. Attackers with physical access can reset devices to factory state, potentially exfiltrating sensitive data displayed or stored on the kiosk, modifying content or functionality, or rendering the device inoperable. This is particularly concerning in retail, hospitality, healthcare, and government settings where kiosks handle customer interactions or restricted information. Affected businesses may experience service interruptions, data breaches, compliance violations, and loss of customer trust.

Affected systems

The vulnerability affects Code 27 Companion Hub devices. Specific version information is not provided in the source data; contact the vendor for a definitive list of affected product versions or verify against Code 27's security advisory.

Exploitability

Exploitation requires physical access to the device and is relatively straightforward—an attacker can simply initiate a factory reset, typically via physical buttons or bootloader interface, without needing authentication credentials or specialized tools. The low attack complexity and lack of prerequisites (no user interaction required, no authentication needed) make this practical for attackers who can physically access the device. However, the physical access requirement significantly limits the attack surface in most organizational contexts.

Remediation

Verify that Code 27 has released a firmware or software patch that implements proper authentication or protection of the factory reset function. Patch management should prioritize devices deployed in public or semi-supervised environments. Additionally, implement compensating controls: secure physical access to kiosk devices via tamper-evident enclosures, locked mounting, surveillance, or restricting placement to staff-only areas. Consider disabling or password-protecting the factory reset function if the firmware or device configuration allows. Organizations should also review whether kiosk mode restrictions are the sole security control and implement layered defenses.

Patch guidance

Consult Code 27's official security advisory to identify patched firmware versions for the Companion Hub. Test patches in a non-production environment to ensure compatibility with existing kiosk configurations and dependent systems. Prioritize patching devices in high-risk locations (public-facing, unsupervised). Verify after patching that the factory reset function is properly protected and that kiosk restrictions cannot be bypassed via reset.

Detection guidance

Monitor for unexpected factory resets on Code 27 Companion Hub devices via device logs, firmware version changes, or configuration rollbacks. Implement alerting on failed or successful access to bootloader or reset functions. Review physical access logs and surveillance footage for unauthorized handling of devices. Check for suspicious configuration changes immediately following device unavailability. Log and alert on any changes to kiosk mode settings or restrictions.

Why prioritize this

Although CVE-2026-36028 carries a MEDIUM CVSS score, prioritization depends on deployment context. Organizations with devices in public or low-supervision environments should treat this as higher priority due to ease of exploitation and high impact. The vulnerability requires physical access, which significantly reduces risk in secured facilities. However, the complete bypass of kiosk protections and exposure of confidentiality, integrity, and availability warrant prompt patching. Organizations should assess their physical security posture and device deployment model to determine internal severity.

Risk score, explained

CVSS 6.8 (MEDIUM) reflects high impact across all three security dimensions (confidentiality, integrity, availability) but is tempered by the requirement for physical access (AV:P). Attack complexity is low, no privileges are required, and the scope is unchanged. While the damage potential is substantial, the physical access barrier significantly reduces real-world likelihood in most corporate environments. Organizations with strong physical security should assess this as lower risk; those with public-facing or inadequately secured kiosks should assess as higher.

Frequently asked questions

What happens if an attacker performs a factory reset on a Code 27 Companion Hub?

The factory reset process bypasses kiosk mode protections without authentication. The device reverts to factory defaults, and the attacker gains full system access with no restrictions. This allows data theft, system modification, or denial of service.

Who is at risk from this vulnerability?

Organizations deploying Code 27 Companion Hub devices in public, semi-supervised, or physically accessible environments—such as retail stores, hotels, airports, hospitals, or government buildings. Organizations with strong physical security and devices in restricted-access areas face lower risk.

Is there a workaround if a patch is not yet available?

Primary mitigations are physical: secure device enclosures, locked mounting, surveillance monitoring, and restricting access to staff-only areas. If the firmware or device config allows, password-protect or disable the factory reset function. These are compensating controls, not permanent solutions; a software patch from Code 27 is required for full remediation.

Will this vulnerability be added to the KEV Catalog?

As of the current data, CVE-2026-36028 is not listed in the CISA Known Exploited Vulnerabilities Catalog. However, status can change; monitor CISA alerts for updates. Continue monitoring for public exploit code or active exploitation reports.

This analysis is provided for informational purposes and reflects information available as of the publication date. CVSS scores, affected versions, and patch details are derived from the source vulnerability record. Organizations must verify patch availability and applicability against Code 27's official security advisories. SEC.co makes no warranty regarding the completeness or accuracy of remediation guidance; security decisions should involve your organization's security and risk teams. Physical security controls and patch testing are the responsibility of the deploying organization. Continuously monitor vendor updates and threat intelligence feeds for evolving information on this vulnerability. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).