The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://community.acer.com/en/kb/articles/19707 |
|
History
Thu, 04 Jun 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands. | |
| Title | Elevated Root Command Execution via ai_cmd Sockets | |
| Weaknesses | CWE-489 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Acer
Published:
Updated: 2026-06-04T04:08:08.913Z
Reserved: 2026-05-28T02:46:15.560Z
Link: CVE-2026-49188
No data.
Status : Received
Published: 2026-06-04T06:16:24.583
Modified: 2026-06-04T06:16:24.583
Link: CVE-2026-49188
No data.
OpenCVE Enrichment
Updated: 2026-06-04T06:30:07Z
Weaknesses