CVE-2026-50604 Details
Description
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially allowing access to functionality that should be restricted.
A vulnerability exists in the Acer Agent Service component of NitroSense and PredatorSense. The issue arises because the socket handshake process fails to properly authenticate connections before granting access to the service. This flaw could allow unauthorized connections to be established, potentially providing access to restricted functionality.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 17, 2026CISA-ADP
Assessed Sep 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.acer.com/en/kb/articles/19871 | Acer | Content WallVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | Acer |
Affected Products
| Product | Versions |
|---|---|
| Acer Agent Service | All versions |
CPE
Remediation
| |
| Acer NitroSense | All versions |
CPE
Remediation
| |
| Acer PredatorSense | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | CISA-ADP |
| Sep 17, 2026 | CVE Modified | Acer |
| Sep 17, 2026 | New CVE Received | Acer |
Volerion