CVE-2026-49197

Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails.

critical 9.8 CVSS 3.1
Published: May 29, 2026
Modified: Jun 8, 2026

Description

Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails.

References

Related CVEs