CVE-2026-68928: CWE-749: Exposed Dangerous Method or Function in Acode-Foundation Acode
Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins/terminal/src/android/TerminalService.java does not verify the caller. Any installed Android application can bind the service and send MSG_EXEC with an attacker-controlled cmd value, which the terminal implementation passes to ProcessBuilder with sh -c inside Acode's UID. This allows a zero-permission local application to execute commands with access to Acode private data, remote credentials, Storage Access Framework grants, and runtime permissions without additional interaction at attack time. This issue is fixed in version 1.12.7.
AI Analysis
Technical Summary
The vulnerability in Acode (CVE-2026-68928) arises because the TerminalService is declared as an exported service without binding permission enforcement, and the service does not verify the caller. This allows any installed Android application with no permissions to bind to the service and send a MSG_EXEC message containing an attacker-controlled command. The command is executed via ProcessBuilder with 'sh -c' under Acode's UID, enabling execution of arbitrary commands with Acode's privileges. This can expose private data, remote credentials, Storage Access Framework grants, and runtime permissions. The vulnerability affects versions >=1.11.6 and <1.12.7 and is resolved in version 1.12.7.
Potential Impact
An attacker with a zero-permission local Android application can execute arbitrary commands within the security context of Acode, potentially accessing sensitive private data, remote credentials, and granted permissions without user interaction. This elevates the risk of data compromise and unauthorized actions on the device under Acode's privileges.
Mitigation Recommendations
Upgrade Acode to version 1.12.7 or later, where this vulnerability is fixed by enforcing binding permissions and caller verification on the TerminalService. Until then, avoid installing untrusted applications that could exploit this service.
CVE-2026-68928: CWE-749: Exposed Dangerous Method or Function in Acode-Foundation Acode
Description
Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins/terminal/src/android/TerminalService.java does not verify the caller. Any installed Android application can bind the service and send MSG_EXEC with an attacker-controlled cmd value, which the terminal implementation passes to ProcessBuilder with sh -c inside Acode's UID. This allows a zero-permission local application to execute commands with access to Acode private data, remote credentials, Storage Access Framework grants, and runtime permissions without additional interaction at attack time. This issue is fixed in version 1.12.7.
CVSS v3.1
Score 8.6high
Affected software
Acode-Foundation
Acode
pkg:github/acode-foundation/AcodeRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Acode (CVE-2026-68928) arises because the TerminalService is declared as an exported service without binding permission enforcement, and the service does not verify the caller. This allows any installed Android application with no permissions to bind to the service and send a MSG_EXEC message containing an attacker-controlled command. The command is executed via ProcessBuilder with 'sh -c' under Acode's UID, enabling execution of arbitrary commands with Acode's privileges. This can expose private data, remote credentials, Storage Access Framework grants, and runtime permissions. The vulnerability affects versions >=1.11.6 and <1.12.7 and is resolved in version 1.12.7.
Potential Impact
An attacker with a zero-permission local Android application can execute arbitrary commands within the security context of Acode, potentially accessing sensitive private data, remote credentials, and granted permissions without user interaction. This elevates the risk of data compromise and unauthorized actions on the device under Acode's privileges.
Mitigation Recommendations
Upgrade Acode to version 1.12.7 or later, where this vulnerability is fixed by enforcing binding permissions and caller verification on the TerminalService. Until then, avoid installing untrusted applications that could exploit this service.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-31T21:49:24.927Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aada35c55bf5e2cf587fb10
Added to database: 09/18/2026, 20:47:24 UTC
Last enriched: 09/18/2026, 21:01:39 UTC
Last updated: 09/18/2026, 22:12:49 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.