CVE-2026-50604 PUBLISHED

Unauthenticated Access Vulnerability in NitroSense and PredatorSense Software

Assigner: Acer
Reserved: 05.06.2026 Published: 17.09.2026 Updated: 17.09.2026

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially allowing access to functionality that should be restricted.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
CVSS Score: 4.9

Product Status

Vendor Acer
Product Agent Service
Versions Default: unaffected
  • affected from * to 1.2.110.2 (incl.)

Solutions

Update to one of the following versions or later:

  • NitroSense v5.2.84
  • PredatorSense v5.2.109

Credits

  • Tolga Cohce reporter

References

Problem Types

  • CWE-306 Missing Authentication for Critical Function CWE

Impacts

  • CAPEC-115 Authentication Bypass