Description
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially allowing access to functionality that should be restricted.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to one of the following versions or later: * NitroSense v5.2.84 * PredatorSense v5.2.109
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://community.acer.com/en/kb/articles/19871 |
|
History
Thu, 17 Sep 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially allowing access to functionality that should be restricted. | |
| Title | Unauthenticated Access Vulnerability in NitroSense and PredatorSense Software | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Acer
Published:
Updated: 2026-09-17T04:06:40.354Z
Reserved: 2026-06-05T07:22:32.054Z
Link: CVE-2026-50604
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-306
Missing Authentication for Critical Function