CVE Watchtower β Back to CVE ListCVE-2026-49197NVDDescriptionWeb endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails.Severity LevelUNKNOWNPublished Date29/05/2026Last Modified29/05/2026Exploitation Status????Referenceshttps://community.acer.com/en/kb/articles/19672