CVE-2026-50606

Summary

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions.

Affected Software

VendorProductVersion RangeStatus
AcerSystem Monitoring* <= 1.0.19.2affected

Weaknesses

  • CWE-321: CWE-321 Hardcoded AES-128-ECB Key

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References