CVE-2026-49189
HIGH WAF: Low
CVSS 7.8
Published: 2026-06-04
CWE-269
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.
WAF Coverage Analysis
Improper Privilege Management
Low WAF Coverage
OWASP: A01:2021 Broken Access Control
Affected Software
| Vendor | Product | Version |
|---|---|---|
| acer | connect_m6e_5g_firmware | up to m6e_ai_1.00.000019 |
References
- community.acer.com (Mitigation, Vendor Advisory)