Exported Service Vulnerability in Acode Android Editor
CVE-2026-68928

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-68928?

Acode, an Android text and code editor, has a vulnerability due to an exported service, com.foxdebug.acode.rk.exec.terminal.TerminalService, that lacks binding permission and caller verification. This flaw enables any installed Android application to bind to the service, allowing it to execute commands controlled by an attacker. The commands can access sensitive Acode private data, including remote credentials and permissions, creating a significant security risk. This issue has been resolved in version 1.12.7.

Affected Version(s)

Acode >= 1.11.6, < 1.12.7

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.