PatchSiren

Acer CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Acer CVE published 2026-09-23

CVE-2026-50228

CVE-2026-50228 debrief based on the supplied source corpus. The vulnerability exists in Acer NitroSense software versions up to and including 5.2.63, which exposes an Electron DevTools endpoint on localhost TCP port 9993. This allows unauthenticated local attackers to execute JavaScript in the privileged application context, potentially leading to arbitrary code execution. Defenders should assess exposure [truncated]

MEDIUM Acer CVE published 2026-09-23

CVE-2026-50227

CVE-2026-50227 debrief based on the supplied source corpus. The vulnerability is a medium-severity issue in Acer NitroSense software, allowing unauthenticated local attackers to execute arbitrary commands. This could lead to potential unauthorized access to sensitive data and possible command execution in the application context. Defenders should verify exposure, assess potential impact, and implement com [truncated]

HIGH Acer CVE published 2026-09-17

CVE-2026-50610

A vulnerability in the Acer System Monitoring component, included with NitroSense and PredatorSense, allows authenticated local users to access a privileged service and perform unauthorized registry modifications. This could potentially lead to local privilege escalation. The vulnerability is considered high-severity and requires prompt attention from system administrators and security teams responsible f [truncated]

HIGH Acer CVE published 2026-09-17

CVE-2026-50609

A vulnerability in Acer System Monitoring, part of NitroSense and PredatorSense, may allow authenticated local users to perform unauthorized registry operations via a privileged Named Pipe service with insufficient access controls. This could lead to privilege escalation or system compromise in certain situations. The vulnerability affects systems with NitroSense and PredatorSense installed, and defenders [truncated]

LOW Acer CVE published 2026-09-17

CVE-2026-50608

A vulnerability in the Acer System Monitoring component of NitroSense and PredatorSense allows unauthorized access to service functionality due to a lack of authentication in the WebSocket handshake process. This issue may enable attackers to interact with the service under certain circumstances, potentially leading to unauthorized access or other malicious activities. Defenders should assess exposure and [truncated]

LOW Acer CVE published 2026-09-17

CVE-2026-50607

A vulnerability was identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket service listens on all network interfaces, potentially exposing it to unintended network access. This configuration may allow unauthorized access to the service, which could lead to security issues. Defenders should verify and restrict network exposure of the Acer System Monitor [truncated]

LOW Acer CVE published 2026-09-17

CVE-2026-50606

A vulnerability in Acer System Monitoring, part of NitroSense and PredatorSense, uses a hard-coded AES encryption key. This allows a local attacker, under certain circumstances, to access protected information or perform unauthorized actions. The vulnerability has a low CVSS score of 1.2 and is considered low-severity. Defenders and administrators should assess exposure and verify local access controls. T [truncated]

HIGH Acer CVE published 2026-09-17

CVE-2026-50605

A vulnerability in the Acer Agent Service component of NitroSense and PredatorSense allows an authenticated local user to perform unauthorized registry operations due to insufficient access controls. This could lead to privilege escalation or system compromise in certain situations. The vulnerability has a high severity score and defenders should prioritize verifying and mitigating this vulnerability, esp [truncated]

MEDIUM Acer CVE published 2026-09-17

CVE-2026-50604

A vulnerability in the Acer Agent Service component of NitroSense and PredatorSense allows unauthorized access due to a lack of authentication in the socket handshake process. This issue, tracked as CVE-2026-50604, has a CVSS score of 4.9 and is considered medium severity. The vulnerability was published on 2026-09-17T05:17:01.943Z and last modified on 2026-09-18T16:25:08.493Z.

MEDIUM Acer CVE published 2026-09-17

CVE-2026-50603

A vulnerability in the Acer Agent Service component of NitroSense and PredatorSense uses a hard-coded AES encryption key. This allows a local attacker to access protected information or perform unauthorized actions under certain circumstances. The Acer Agent Service component included with NitroSense and PredatorSense uses a hard-coded AES encryption key, which may allow a local attacker to access protect [truncated]

HIGH Acer CVE published 2026-08-17

CVE-2026-50602

A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned to an application executable used by the Planet9 background service. The service runs with SYSTEM privileges, while the affected executable grants excessive permissions to non-administrative users. As a result, an authenticated local user could potentially modify or replace the executable and execute arbitra [truncated]

MEDIUM Acer CVE published 2026-08-17

CVE-2026-50601

A security vulnerability has been identified in the Planet9 desktop application where a hardcoded read-only API key permitted unauthorized access to internal repositories. An attacker could exploit this access to extract embedded administrative keys and secrets, potentially allowing them to gain administrative access to repository infrastructure and modify software source code.

MEDIUM Acer CVE published 2026-06-04

CVE-2026-50226

The AcerConnect OTA application had a security issue (CVE-2026-50226) where fixed AES-128-CBC keys were used, allowing attackers to forge authorization credentials for any IMEI number. This vulnerability, with a CVSS score of 6.9, enabled unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links.

HIGH Acer CVE published 2026-06-04

CVE-2026-50225

CVE-2026-50225 is a HIGH severity vulnerability with a CVSS score of 8.8. The vulnerability exists in the registration path /v1/account/register, which provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database. The vulnerability was published on [cvePublishedAt]2026-06-04T10:16:40.123Z[/cvePublishedAt] and modified on [cveModifiedAt]2026-06-08T12:58:13.150Z[/cveModifiedAt].

MEDIUM Acer CVE published 2026-06-04

CVE-2026-50224

The CVE-2026-50224 vulnerability affects the Acer Connect M6E 5G product. The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API endpoints reachable over the WAN. This issue has a CVSS score of 6.9 and is classified as MEDIUM severity.

CRITICAL Acer CVE published 2026-06-04

CVE-2026-50214

CVE-2026-50214 is a critical vulnerability with a CVSS score of 9.3, affecting the /v1/Plan service, which relies entirely on a shared global API token for full administrative management. This allows for arbitrary creation of zero-cost network access plans. The vulnerability was published on 2026-06-04T10:16:39.850Z and modified on 2026-06-08T12:56:12.743Z.

HIGH Acer CVE published 2026-06-04

CVE-2026-50213

CVE-2026-50213 is a high-severity vulnerability with a CVSS score of 8.7. The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings. This issue was published on 2026-06-04T09:16:29.987Z and last modified on 2026-06-04T19:10:08.420Z.

HIGH Acer CVE published 2026-06-04

CVE-2026-50212

CVE-2026-50212 is a HIGH severity vulnerability with a CVSS score of 7.1. The vulnerability is caused by weak validation logic within device dissociation API routines, allowing a remote entity to forcefully unbind unrelated user endpoints, resulting in a severe denial of service.

HIGH Acer CVE published 2026-06-04

CVE-2026-50211

A high-severity vulnerability, CVE-2026-50211, was discovered in Acer Connect M6E 5G firmware. The vulnerability has a CVSS score of 8.8 and allows malicious apps to gain write privileges to internal NVRAM registers due to leftover engineering diagnostics and factory-level diagnostic software exposed on retail builds.

MEDIUM Acer CVE published 2026-06-04

CVE-2026-50210

CVE-2026-50210 is a vulnerability in Acer Connect M6E 5G firmware. The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption. This vulnerability has a CVSS score of 6.9 and a severity of MEDIUM.

CRITICAL Acer CVE published 2026-06-04

CVE-2026-50209

A critical vulnerability in Acer Connect M6E 5G firmware allows malicious software on the device to intercept and exploit broadcast events, rewriting the default Mobile Device Management (MDM) endpoint address. This redirects administrative control to an attacker-controlled server, effectively transferring device ownership. The flaw is rated CVSS 4.0 critical with high impacts across confidentiality, inte [truncated]

CRITICAL Acer CVE published 2026-06-04

CVE-2026-50208

Acer Connect M6E 5G firmware contains critical TLS security weaknesses. TrustAllCerts routines disable standard certificate validation, and hard-coded DES symmetric encryption keys are present. A network-positioned attacker could exploit these flaws in a Man-in-the-Middle (MITM) scenario to decrypt network traffic. The vulnerability affects Connect M6E 5G firmware versions up to and including M6E_AI_1.00. [truncated]

HIGH Acer CVE published 2026-06-04

CVE-2026-50207

A local privilege escalation vulnerability in Acer Connect M6E 5G firmware allows authenticated local attackers to send unverified AT commands through the Binder interface. The flaw enables reading baseband files or disabling cellular connectivity. The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory), though the description indicates an AT command injecti [truncated]

CRITICAL Acer CVE published 2026-05-29

CVE-2026-49197

Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails.

HIGH Acer CVE published 2026-05-29

CVE-2026-49196

A command injection vulnerability exists in a Wi-Fi device blocking feature due to insufficient sanitization of MAC address input. An attacker with high privileges can inject and execute arbitrary shell commands by supplying a crafted MAC address. The vulnerability is rated HIGH severity with a CVSS score of 8.6. The affected vendor is identified as Acer based on reference domain evidence, though this att [truncated]

HIGH Acer CVE published 2026-05-29

CVE-2026-49195

An unauthenticated debug service vulnerability exposes the /sbin/mtk_dut binary on TCP port 9000, allowing any LAN-based attacker to execute arbitrary UCC commands without authentication. The vulnerability carries a HIGH severity CVSS score of 8.7. The vendor attribution to Acer is based on a reference domain candidate with low confidence and requires review. The CVE was published on 2026-05-29 and remain [truncated]

HIGH Acer CVE published 2026-05-28

CVE-2026-9789

A local privilege escalation vulnerability in Acer NitroSense software versions prior to 3.01.3052 allows authenticated low-privileged users to delete arbitrary files with SYSTEM privileges. The PSAdminAgent service creates a Named Pipe with a weak Access Control List (ACL), permitting any authenticated local user to connect and send commands. The service fails to validate caller privileges before executi [truncated]

MEDIUM Acer CVE published 2026-05-25

CVE-2026-9490

A local denial-of-service vulnerability exists in Acer Care Center's ACCSvc service. The service creates a Named Pipe with a weak Security Descriptor, allowing an authenticated local user to connect and send a specially crafted message (type 0x03) that causes the service to terminate with exit code 1067 (ERROR_PROCESS_ABORTED). This vulnerability requires local access and valid user credentials, limiting [truncated]

HIGH Acer CVE published 2026-05-25

CVE-2026-9489

NitroSense 3.x before 3.01.3052 contains a Local Privilege Escalation (LPE) vulnerability. The application exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. This Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY SYSTEM privileges and to delete arbitrary files with SYSTEM privileges. By leveraging this, an att [truncated]

HIGH Acer CVE published 2026-05-08

CVE-2026-8069

The PredatorSense program, versions 3.00.3136 to 3.00.3196, contains a Local Privilege Escalation (LPE) vulnerability. This vulnerability arises from a misconfigured Windows Named Pipe that uses a custom protocol to invoke internal functions, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY SYSTEM privileges and delete arbitrary files with SYSTEM privileges. System adminis [truncated]