Medium severityNVD Advisory· Published Jun 4, 2026
CVE-2026-50226
CVE-2026-50226
Description
Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
1- Acer: Five Vulnerabilities Disclosed Together, Including Two Critical FlawsVypr Intelligence · Jun 4, 2026