CVE-2026-49198: Predator Connect W6x: MQTT Broker Access Control
Published May 29, 2026
·Updated
Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorized actors.
Affected Software
3 affected components
Predator Connect W6x MQTT broker
All of the following
Acer Predator Connect W6x Firmware<=w6x_gbl_2.00.000005
Acer Predator Connect W6x
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Predator Connect W6x: MQTT Broker Access Controlto a version that resolves this vulnerability.Fixed in W6x_GBL_2.00.000008
Event History
May 29, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-49198?
CVE-2026-49198 has a severity rating of high with a CVSS score of 8.3.
2
How do I fix CVE-2026-49198?
To fix CVE-2026-49198, upgrade to firmware version W6x_GBL_2.00.000008.
3
What type of vulnerability is CVE-2026-49198?
CVE-2026-49198 is related to improper access control in the MQTT broker.
4
Does CVE-2026-49198 expose sensitive data?
Yes, CVE-2026-49198 allows unauthorized actors access to all MQTT traffic due to wildcard topic subscriptions.
5
Which software is affected by CVE-2026-49198?
CVE-2026-49198 affects the Predator Connect W6x MQTT broker.