CVE-2026-50608: Authentication Vulnerability in NitroSense and PredatorSense Software
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before allowing connections to the service. Under certain circumstances, unauthorized access to service functionality may be possible.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NitroSenseto a version that resolves this vulnerability.Fixed in 5.2.84 - Upgrade
Upgrade
PredatorSenseto a version that resolves this vulnerability.Fixed in 5.2.109
Event History
Frequently Asked Questions
Which systems are potentially exposed?
Systems running Acer NitroSense or Acer PredatorSense that include the Acer System Monitoring component are potentially affected.
What must an attacker do to exploit this issue?
The attacker must be able to connect to the Acer System Monitoring service and complete a WebSocket handshake. The issue is that this handshake may permit connections without properly requiring authentication.
Is unauthorized access guaranteed after connecting?
No. The available information states that unauthorized access to service functionality may be possible only under certain circumstances.