CVE-2026-36028 Details
Description
A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass kiosk restrictions via a factory reset
A vulnerability in the Code 27 Companion Hub allows an attacker with physical access to bypass kiosk restrictions by performing a factory reset. This reset wipes the userdata partition where kiosk applications are installed, leading the device to boot into a standard, unrestricted Android environment. From this environment, an attacker can re-enable developer options, sideload arbitrary applications, and execute them to gain control over the device.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 8, 2026CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://code.com | [email protected] | Broken Link |
| https://companion.com | [email protected] | Broken Link |
| https://github.com/redr0nin/Code-27-Companion-Hub-Exploits | [email protected] | BundleExploitTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Code 27 3D Companion Hub | 1.2.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | [email protected] |
Volerion