The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://community.acer.com/en/kb/articles/19707 |
|
History
Thu, 04 Jun 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping. | |
| Title | Summary Service Insecure Direct Object Reference | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Acer
Published:
Updated: 2026-06-04T05:43:55.875Z
Reserved: 2026-05-28T02:46:15.561Z
Link: CVE-2026-49192
No data.
Status : Received
Published: 2026-06-04T07:16:27.153
Modified: 2026-06-04T07:16:27.153
Link: CVE-2026-49192
No data.
OpenCVE Enrichment
Updated: 2026-06-04T08:30:09Z
Weaknesses