CVE-2026-50604: Unauthenticated Access Vulnerability in NitroSense and PredatorSense Software
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially allowing access to functionality that should be restricted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NitroSenseto a version that resolves this vulnerability.Fixed in 5.2.84 - Upgrade
Upgrade
PredatorSenseto a version that resolves this vulnerability.Fixed in 5.2.109 - Compensating control
Until NitroSense/PredatorSense are updated to the stated versions or later, restrict network access to the Acer Agent Service (the service in the NitroSense/PredatorSense package) so unauthenticated connections cannot reach the socket handshake endpoint.