CVE-2026-49197

Severity CVSS v4.0:
CRITICAL
Type:
CWE-287 Authentication Issues
Publication date:
29/05/2026
Last modified:
29/05/2026

Description

Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails.

References to Advisories, Solutions, and Tools