CVE-2026-49203

Severity CVSS v4.0:
HIGH
Type:
CWE-287 Authentication Issues
Publication date:
04/06/2026
Last modified:
04/06/2026

Description

Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.

References to Advisories, Solutions, and Tools