CVE-2026-50209
A critical flaw in Acer Connect M6E 5G devices lets malicious software change the device’s Mobile Device Management (MDM) endpoint address. By doing so, an attacker can take over administrative control of the device. The vulnerability is rated CVSS 9.3, indicating a severe risk.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Acer Connect M6E 5G firmware and the corresponding device model.
Real-world impact
An attacker who exploits this flaw can redirect the device’s management traffic to a server they control, effectively taking full administrative control over the device. This could allow the attacker to install additional malware, exfiltrate data, or disrupt device operations.
Why this severity
The CVSS score of 9.3 reflects the vulnerability’s high impact on confidentiality, integrity, and availability. The flaw allows local attackers with low privileges to modify critical configuration (MDM endpoint), leading to complete administrative takeover. The lack of user interaction and the ability to execute from local access make it a critical threat.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jun 4, 2026 · Jun 4, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 22, 2026 · 13d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- community.acer.com/en/kb/articles/19707mitigationvendor advisory