CVE-2026-49004
The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with root privileges, and is protected by weak credentials. The database supports the COPY FROM PROGRAM syntax, allowing local attackers to bypass Android's permission sandbox and gain full root access.
Published:Aug 5, 2026
Last Modified:Aug 5, 2026
EPS:Aug 5, 2026
EPSS Score:0.00689
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Zte
Product
Nx799j (red Magic 11 Air)
Zte
Nx799j (red Magic 11 Air)
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
