Description
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially allowing access to functionality that should be restricted.
Published: 2026-09-17
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Apply Patch
AI Analysis

Impact

A flaw in the socket handshake of the Acer Agent Service for NitroSense and PredatorSense allows a remote party to establish a connection without authenticating. The missing validation can expose functionality that should be restricted, creating a risk of unauthorized operations against the service.

Affected Systems

All Acer Agent Service installations bundled with NitroSense and PredatorSense, including versions older than NitroSense v5.2.84 and PredatorSense v5.2.109. The vulnerability applies to the component that manages incoming socket connections.

Risk and Exploitability

The CVSS score of 4.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. Because the flaw is an authentication bypass (CWE‑306), an attacker only needs the ability to reach the service over the network; no additional privileges or code execution are required. The likely attack vector is an inbound network connection to the Agent Service port, inferred from the description that the socket handshake does not require authentication. The vulnerability is not listed in the CISA KEV catalog, further indicating that widespread exploitation has not been observed yet. Nonetheless, the potential to gain unauthorized access to privileged service functionality warrants prompt remediation.

Generated by OpenCVE AI on September 17, 2026 at 22:32 UTC.

Remediation

Vendor Solution

Update to one of the following versions or later: * NitroSense v5.2.84 * PredatorSense v5.2.109


OpenCVE Recommended Actions

  • Upgrade NitroSense to version 5.2.84 or later or upgrade PredatorSense to version 5.2.109 or later, which contain the socket authentication fix.
  • Restrict network access to the Agent Service by configuring firewalls or ACLs so that only trusted hosts can initiate a connection to the service port.
  • After applying the update, monitor network traffic for unexpected or unauthorized connections to the Agent Service to detect any attempted exploitation.

Generated by OpenCVE AI on September 17, 2026 at 22:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Acer
Acer agent Service
Vendors & Products Acer
Acer agent Service

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially allowing access to functionality that should be restricted.
Title Unauthenticated Access Vulnerability in NitroSense and PredatorSense Software
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 4.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:U'}


Subscriptions

Acer Agent Service
cve-icon MITRE

Status: PUBLISHED

Assigner: Acer

Published:

Updated: 2026-09-17T12:52:56.787Z

Reserved: 2026-06-05T07:22:32.054Z

Link: CVE-2026-50604

cve-icon Vulnrichment

Updated: 2026-09-17T12:52:45.471Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T05:17:01.943

Modified: 2026-09-18T16:25:08.493

Link: CVE-2026-50604

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:02:58Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function