Description
A security vulnerability has been identified in the Planet9 desktop application where a hardcoded read-only API key permitted unauthorized access to internal repositories. An attacker could exploit this access to extract embedded administrative keys and secrets, potentially allowing them to gain administrative access to repository infrastructure and modify software source code. To mitigate this security risk, Acer has released an update to resolve the issue.
Published: 2026-08-17
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Planet9 desktop application where a hardcoded read‑only API key is embedded in the binary. This key grants access to internal repositories, enabling an attacker to extract administrative keys and secrets. With those credentials, the attacker can obtain administrative rights to the repository infrastructure, potentially modifying software source code and compromising the integrity of the codebase.

Affected Systems

All Acer Planet9 desktop application clients prior to version v2.8.128 are affected. The vendor provides a fix in version v2.8.128, which removes the hardcoded credential and automatically updates clients when available.

Risk and Exploitability

The CVSS score of 6.6 indicates moderate severity; EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would need local or privileged access to the target machine to extract the hardcoded key, or that the attack could target a system already running the application. The description does not mention a remote attack path, so indirect exploitation appears unlikely without additional weaknesses.

Generated by OpenCVE AI on August 17, 2026 at 03:50 UTC.

Remediation

Vendor Solution

Planet9 Version v2.8.128 contains a resolution to this vulnerability. The application will automatically update to the patched version (v2.8.128) in the background.


OpenCVE Recommended Actions

  • Deploy the vendor‑provided update to Planet9 v2.8.128 or later to remove the hardcoded API key.
  • Disable any components that rely on the old key and reconfigure repository authentication to use secure, dynamic credentials.
  • If an immediate patch is not possible, isolate the application or block its network traffic to repository endpoints to prevent unauthorized use of the compromised key.

Generated by OpenCVE AI on August 17, 2026 at 03:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Acer
Acer planet9 Desktop Application
Vendors & Products Acer
Acer planet9 Desktop Application

Mon, 17 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been identified in the Planet9 desktop application where a hardcoded read-only API key permitted unauthorized access to internal repositories. An attacker could exploit this access to extract embedded administrative keys and secrets, potentially allowing them to gain administrative access to repository infrastructure and modify software source code. To mitigate this security risk, Acer has released an update to resolve the issue.
Title Planet9 Hardcoded Credentials Vulnerability Information
Weaknesses CWE-798
References
Metrics cvssV4_0

{'score': 6.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U'}


Subscriptions

Acer Planet9 Desktop Application
cve-icon MITRE

Status: PUBLISHED

Assigner: Acer

Published:

Updated: 2026-08-17T15:57:28.016Z

Reserved: 2026-06-05T07:22:32.054Z

Link: CVE-2026-50601

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-17T03:16:50.703

Modified: 2026-09-03T16:41:09.297

Link: CVE-2026-50601

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T10:58:09Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials