Description
Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins/terminal/src/android/TerminalService.java does not verify the caller. Any installed Android application can bind the service and send MSG_EXEC with an attacker-controlled cmd value, which the terminal implementation passes to ProcessBuilder with sh -c inside Acode's UID. This allows a zero-permission local application to execute commands with access to Acode private data, remote credentials, Storage Access Framework grants, and runtime permissions without additional interaction at attack time. This issue is fixed in version 1.12.7.
Published: 2026-09-18
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Arbitrary Code Execution
Action: Immediate Patch
AI Analysis

Impact

Acode versions 1.11.6 through 1.12.7 expose an exported service that accepts a command from any installed Android app. The service passes the received command to Java's ProcessBuilder with "sh -c", executing it under Acode's UID. An attacker can thus run arbitrary shell commands as Acode, gaining access to Acode private data, stored credentials, File‑Picker grants, and any runtime permissions that Acode holds, all without needing any permissions for the malicious app itself.

Affected Systems

The vulnerability affects the Acode app from the Acode‑Foundation publisher, specifically releases between 1.11.6 and 1.12.7 inclusive. Version 1.12.7 includes the fix that removes the exporter without proper permission checks.

Risk and Exploitability

The CVSS score of 8.6 classifies this as a high‑severity flaw. EPSS is unavailable, but the lack of a binding permission means a zero‑permission, local Android application can exploit the vulnerability immediately upon installing. No external network access is required; the attack vector is local. Because the flaw allows remote commands to run within Acode’s process space, it is also a local privilege escalation that can be abused to elevate or compromise user data on the device.

Generated by OpenCVE AI on September 19, 2026 at 11:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Acode to version 1.12.7 or later, which removes the exported service and adds caller verification.
  • If an upgrade is not yet possible, uninstall the affected Acode version or replace it with a non‑vulnerable release.
  • As a temporary safeguard, ensure that only trusted applications are installed and consider restricting installation from unknown sources while an update is applied.

Generated by OpenCVE AI on September 19, 2026 at 11:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Acode
Acode acode
Vendors & Products Acode
Acode acode

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins/terminal/src/android/TerminalService.java does not verify the caller. Any installed Android application can bind the service and send MSG_EXEC with an attacker-controlled cmd value, which the terminal implementation passes to ProcessBuilder with sh -c inside Acode's UID. This allows a zero-permission local application to execute commands with access to Acode private data, remote credentials, Storage Access Framework grants, and runtime permissions without additional interaction at attack time. This issue is fixed in version 1.12.7.
Title Acode: Exported TerminalService (bundled terminal plugin) lets any installed app execute arbitrary shell commands as Acode
Weaknesses CWE-749
CWE-862
CWE-926
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T18:27:19.972Z

Reserved: 2026-07-31T21:49:24.927Z

Link: CVE-2026-68928

cve-icon Vulnrichment

Updated: 2026-09-21T18:27:16.322Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T21:17:14.377

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-68928

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:24:32Z

Weaknesses
  • CWE-749

    Exposed Dangerous Method or Function

  • CWE-862

    Missing Authorization

  • CWE-926

    Improper Export of Android Application Components