{"id":"CVE-2026-50608","title":"A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense","summary":"A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before allowing connections to the service. …","severity":"low","cvss":1.2,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U","cwe":["CWE-306"],"vendor":"Acer","product":"System Monitoring","affected":["system_monitoring <= 1.0.19.2"],"published":"2026-09-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T16:25:08.493","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-50608","references":[{"url":"https://community.acer.com/en/kb/articles/19875","label":"8fc372e3-d9c5-46e4-9410-38469745c639"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-17T12:25:32.773472Z"},"cvssSource":"cna","ingestedAt":"2026-09-17T09:14:58.452Z","epss":0.00142,"epssPercentile":0.03894,"slug":"CVE-2026-50608","body":"## Overview\n\nA vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before allowing connections to the service. Under certain circumstances, unauthorized access to service functionality may be possible.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":7,"depthScoreParts":{"impact":6.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}