CVE-2026-9789 Details
Description
A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the PSAdminAgent service, which creates a Named Pipe with a weak Access Control List (ACL). This allows any authenticated local user to connect and send commands. Because the service does not check the caller's privileges before running file deletion commands, a low-privileged local user can exploit this to delete arbitrary files with system authority.
A local privilege escalation vulnerability exists in Acer NitroSense software versions prior to 3.01.3052. The issue arises from the PSAdminAgent service, which creates a Named Pipe with a weak Access Control List (ACL). This configuration allows any authenticated local user to connect and send commands. The vulnerability is exploited because the service fails to verify the caller's privileges before executing file deletion commands, enabling a low-privileged local user to delete arbitrary files with system authority.
Users can update to Acer NitroSense version 3.01.3052 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 28, 2026CISA-ADP
Assessed May 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.acer.com/en/kb/articles/19670 | Acer | Content WallVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Acer |
| CWE-269 | Improper Privilege Management | Acer |
| CWE-284 | Improper Access Control | Acer |
| CWE-732 | Incorrect Permission Assignment for Critical Resource | Acer |
Affected Products
| Product | Versions |
|---|---|
| Acer NitroSense | < 3.01.3052 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Acer |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 28, 2026 | New CVE Received | Acer |
Volerion