CVE-2026-8069 Details
Description
PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY\SYSTEM privileges and to delete arbitrary files with SYSTEM privileges. By leveraging this, an attacker can execute arbitrary code on the target system with elevated privileges.
A local privilege escalation vulnerability has been identified in Acer PredatorSense versions 3.00.3136 through 3.00.3196. The issue arises because the program exposes a Windows Named Pipe that, while intended to invoke internal functions via a custom protocol, is misconfigured. This flaw allows any authenticated local user to execute arbitrary code with NT AUTHORITY\SYSTEM privileges and to delete arbitrary files with SYSTEM privileges. Exploiting this vulnerability enables an attacker to execute code on the target system with elevated rights.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.acer.com/en/kb/articles/19652 | Acer | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Acer |
| CWE-269 | Improper Privilege Management | Acer |
| CWE-284 | Improper Access Control | Acer |
| CWE-732 | Incorrect Permission Assignment for Critical Resource | Acer |
Affected Products
| Product | Versions |
|---|---|
| acer nitrosense | >= 3.00.0000, < 3.01.3056 |
CPE
Remediation
| |
| acer predatorsense | >= 3.00.0000, < 3.00.3198 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 12, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | Acer |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 8, 2026 | New CVE Received | Acer |