CVE-2026-50602: Planet9 Incorrect Permission Assignment Vulnerability Information
A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned to an application executable used by the Planet9 background service. The service runs with SYSTEM privileges, while the affected executable grants excessive permissions to non-administrative users. As a result, an authenticated local user could potentially modify or replace the executable and execute arbitrary code with SYSTEM privileges when the service starts or the system is restarted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
PLANET9DAServicefrom your environment.Remove/uninstall the Planet9 background service (PLANET9DAService) as part of the available update that resolves the vulnerability.
- Compensating control
Remove the affected Planet9 executable files that have incorrect permissions as part of the available update, to prevent authenticated local users from modifying/replacing the executable and executing arbitrary code with SYSTEM privileges on service start or system restart.