← Browse

CVE-2026-49203

Medium

Elevated severity or exploit probability.

CVSS base
8.3 HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
EPSS — probability of exploitation (30 days)
0.2%
6.5th percentile
CISA KEV
Not listed
Weakness / dates
CWE-287
Published 2026-06-04 · modified 2026-07-22

CVSS breakdown

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

Attack VectorAAdjacent
Attack ComplexityLLow
Privileges RequiredNNone
User InteractionNNone
ScopeUUnchanged
ConfidentialityLLow
IntegrityHHigh
AvailabilityHHigh

Timeline

Description

Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.

Affected

acer

References

Official: NVD · CVE.org