The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.
History

Thu, 04 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 04 Jun 2026 07:15:00 +0000

Type Values Removed Values Added
Description The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.
Title Summary Service Insecure Direct Object Reference
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Acer

Published:

Updated: 2026-06-04T12:35:37.028Z

Reserved: 2026-05-28T02:46:15.561Z

Link: CVE-2026-49192

cve-icon Vulnrichment

Updated: 2026-06-04T12:35:33.788Z

cve-icon NVD

Status : Received

Published: 2026-06-04T07:16:27.153

Modified: 2026-06-04T07:16:27.153

Link: CVE-2026-49192

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-04T08:30:09Z