CVE-2026-50605 PUBLISHED

Privilege Escalation Vulnerability in NitroSense and PredatorSense Software

Assigner: Acer
Reserved: 05.06.2026 Published: 17.09.2026 Updated: 17.09.2026

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insufficient access controls within a privileged service may allow an authenticated local user to perform unauthorized registry operations. In certain situations, this could lead to privilege escalation or compromise of the affected system.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U
CVSS Score: 7.4

Product Status

Vendor Acer
Product Agent Serivce
Versions Default: unaffected
  • affected from * to 1.2.110.2 (incl.)

Solutions

Update to one of the following versions or later:

  • NitroSense v5.2.84
  • PredatorSense v5.2.109

References

Problem Types

  • CWE-284: Improper Access Control CWE

Impacts

  • CAPEC-233 Privilege Escalation
  • CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels