Instruction Permission Vulnerability in Acer Systems
CVE-2026-49190

9.4CRITICAL

Key Information:

Vendor

Acer

Vendor
CVE Published:
4 June 2026

What is CVE-2026-49190?

An improper permission management vulnerability exists within multiple Acer systems, allowing the system to bypass the evaluation of instructional permissions on various internal operation codes. This flaw can enable unauthorized application installations or the execution of potentially harmful commands, putting systems at risk of exploitation.

Affected Version(s)

Connect M6E 5G Portable WiFi Router *

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ta-Lun Yen
.