Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-49004: PostgreSQL on ZTE Device Misconfigured, Allows Root Access

CVE-2026-49004 CVE-2026-49004
Summary

The ZTE NX799J's built-in PostgreSQL service is misconfigured, allowing an attacker to gain full root access on the device. This is a significant security risk because it could be exploited by a malicious app or a local attacker. To mitigate this, consider updating the device or replacing the PostgreSQL service with a more secure alternative.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
zte nx799j (red magic 11 air) GEN_CN_NX799JV1.0.0B15
Original title
The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with root privileges, a...
Original description
The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with root privileges, and is protected by weak credentials. The database supports the COPY FROM PROGRAM syntax, allowing local attackers to bypass Android's permission sandbox and gain full root access.
Vulnerability type
CWE-89 SQL Injection
Published: 5 Aug 2026 · Updated: 5 Aug 2026 · First seen: 5 Aug 2026