CVE-2026-50225: Account Creation Exhaustion
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Add bot mitigation controls to the /v1/account/register registration endpoint to prevent automated flooding (e.g., rate limiting / bot filtering on requests to /v1/account/register).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50225?
CVE-2026-50225 has a high severity rating of 8.8 on the CVSS scale.
How do I fix CVE-2026-50225?
To mitigate CVE-2026-50225, implement bot mitigation mechanisms on the registration path to prevent automated account creation.
What type of attack does CVE-2026-50225 facilitate?
CVE-2026-50225 facilitates account creation exhaustion attacks by allowing malicious automated systems to flood the database.
Which software is affected by CVE-2026-50225?
CVE-2026-50225 affects the Acer Connect M6e 5g Firmware.
When was CVE-2026-50225 published?
CVE-2026-50225 was published on June 4, 2026.