CVE-2026-50603

Summary

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions.

Affected Software

VendorProductVersion RangeStatus
AcerAgent Service* <= 1.2.110.2affected

Weaknesses

  • CWE-321: CWE-321 Hardcoded AES-128-ECB Key

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References