CVE-2026-50602 PUBLISHED

Planet9 Incorrect Permission Assignment Vulnerability Information

Assigner: Acer
Reserved: 05.06.2026 Published: 17.08.2026 Updated: 17.08.2026

A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned to an application executable used by the Planet9 background service. The service runs with SYSTEM privileges, while the affected executable grants excessive permissions to non-administrative users. As a result, an authenticated local user could potentially modify or replace the executable and execute arbitrary code with SYSTEM privileges when the service starts or the system is restarted.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Acer
Product Planet9 background service
Versions Default: unaffected
  • Version NA is affected

Solutions

An update is available that resolves this vulnerability by removing the affected executable files and uninstalling the background service (PLANET9DAService). Planet9 will automatically upgrade to the latest version.

Credits

  • Tolga Cöhce reporter

References

Problem Types

  • CWE-732 Incorrect Permission Assignment for Critical Resource CWE

Impacts

  • CAPEC-234 Hijacking a Privileged Process