Inadequate Access Control in ZTE Z80 Ultra Systems
CVE-2026-108506

5.5MEDIUM

Key Information:

Vendor

Zte

Status
Vendor
CVE Published:
10 October 2026

What is CVE-2026-108506?

The ZTE Z80 Ultra has a vulnerability in its system interfaces stemming from insufficient authentication mechanisms for invocation. This weakness allows unauthorized third-party applications to exploit the interfaces via reflection, potentially leading to unauthorized access to sensitive information. To mitigate this vulnerability, it is crucial to enhance access control protocols to safeguard user data and maintain system integrity.

Affected Version(s)

Z80 Ultra GEN_ZTE_PQ85A01V1.0.0B27 and prior released versions

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

EliGold
.