CVE-2026-49185: Instruction Injection via FieldX MDM

Published Jun 4, 2026
·
Updated

The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.

Affected Software

3 affected components
FieldX FieldX MDM
All of the following
Acer Connect M6e 5g Firmware<=m6e_ai_1.00.000019
Acer Connect M6e 5g

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Validate and sanitize all payloads received on the adb messaging topic before using them. Do not pass untrusted input directly into Runtime.exec(); implement input validation, command whitelisting, escape or reject dangerous characters, and prefer safer execution methods (e.g., invoking commands with argument arrays rather than via a shell).

    FieldX MDM adb messaging topic handling = validate and sanitize payloads; do not execute untrusted input
  2. Configuration

    If the adb messaging topic is not required, disable it. If it is required, restrict publishing to authenticated and authorized/trusted publishers only and enforce strict access controls on who can send messages to that topic.

    FieldX MDM adb messaging topic = disabled or restricted to trusted publishers
  3. Compensating control

    Restrict network and management access to the device/messaging endpoints: limit access to the adb/messaging interface to trusted IPs and networks via firewall/ACLs, place the management plane behind network isolation (VPN/VPC), and monitor logging/alerts for suspicious command execution attempts.

Event History

Jun 4, 2026
CVE Published
via MITRE·02:55 AM
Data Sourced
via MITRE·02:55 AM
DescriptionWeakness
Data Sourced
via NVD·04:17 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-49185?

The severity of CVE-2026-49185 is rated as critical with a CVSS score of 10.

2

What is CVE-2026-49185?

CVE-2026-49185 is an instruction injection vulnerability in FieldX MDM that allows unverified payloads to be executed via Runtime.exec().

3

How do I fix CVE-2026-49185?

To fix CVE-2026-49185, update to the latest version of FieldX MDM that addresses this vulnerability.

4

What are the potential impacts of CVE-2026-49185?

The potential impacts of CVE-2026-49185 include unauthorized command execution and system compromise.

5

Is CVE-2026-49185 easy to exploit?

Yes, CVE-2026-49185 can be exploited easily due to its nature of passing unverified payloads into Runtime.exec().

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203