CVE-2026-49203: Unauthenticated eSIM Configuration Manipulation
Published Jun 4, 2026
·Updated
Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.
Affected Software
2 affected components
All of the following
Acer Connect M6e 5g Firmware<=m6e_ai_1.00.000019
Acer Connect M6e 5g
Event History
Jun 4, 2026
CVE Published
via MITRE·06:25 AM
Data Sourced
via MITRE·06:25 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-49203?
CVE-2026-49203 has a severity rating of high with a score of 7.2.
2
What systems are affected by CVE-2026-49203?
CVE-2026-49203 affects the Acer Connect M6e 5g Firmware.
3
How do I fix CVE-2026-49203?
To mitigate CVE-2026-49203, ensure that the management API endpoints restrict access based on proper caller authorization.
4
What type of vulnerability is CVE-2026-49203?
CVE-2026-49203 is classified as an unauthenticated eSIM configuration manipulation vulnerability.
5
What can an attacker do with CVE-2026-49203?
An attacker can exploit CVE-2026-49203 to rewrite or delete remote eSIM profiles due to insufficient authorization validation.