PatchSiren cyber security CVE debrief
CVE-2026-9789 Acer CVE debrief
A local privilege escalation vulnerability in Acer NitroSense software versions prior to 3.01.3052 allows authenticated low-privileged users to delete arbitrary files with SYSTEM privileges. The PSAdminAgent service creates a Named Pipe with a weak Access Control List (ACL), permitting any authenticated local user to connect and send commands. The service fails to validate caller privileges before executing file deletion operations, enabling privilege escalation through arbitrary file deletion.
- Vendor
- Acer
- Product
- NitrorSense V3
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-28
- Original CVE updated
- 2026-05-28
- Advisory published
- 2026-05-28
- Advisory updated
- 2026-05-28
Who should care
Organizations deploying Acer NitroSense on Windows endpoints, particularly gaming workstations and laptops. Security teams managing endpoint privilege escalation attack surfaces. System administrators responsible for OEM software inventory and patch management.
Technical summary
The PSAdminAgent service in Acer NitroSense creates a Named Pipe with overly permissive ACL settings, allowing any authenticated local user to establish connections. The service accepts and executes file deletion commands without verifying the requesting user's privilege level. This architectural flaw enables low-privileged users to leverage the service's SYSTEM-level execution context to delete arbitrary files, resulting in local privilege escalation. The vulnerability is classified as HIGH severity with CVSS 4.0 scoring. Multiple CWE classifications apply: CWE-22 (Path Traversal), CWE-269 (Improper Privilege Management), CWE-284 (Improper Access Control), and CWE-732 (Incorrect Permission Assignment for Critical Resource).
Defensive priority
HIGH
Recommended defensive actions
- Upgrade Acer NitroSense to version 3.01.3052 or later
- Audit systems for NitroSense installations prior to 3.01.3052
- Review Named Pipe ACL configurations on managed endpoints
- Monitor for suspicious file deletion activity from PSAdminAgent service
- Apply principle of least privilege to local user accounts
Evidence notes
CVE published 2026-05-28; NVD record shows Deferred status with CVSS 4.0 vector. Acer knowledge base article referenced as primary source. Vendor identification marked low confidence requiring review despite Acer domain reference.
Official resources
-
CVE-2026-9789 CVE record
CVE.org
-
CVE-2026-9789 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
8fc372e3-d9c5-46e4-9410-38469745c639
2026-05-28