---
id: CVE-2026-50227
title: >-
  An unauthenticated local attacker can connect to the MQTT broker over its
  localhost WebSocket endpoint in Acer NitroSense software (versions up to and
  including 5.2.62)
summary: >-
  An unauthenticated local attacker can connect to the MQTT broker over its
  localhost WebSocket endpoint in Acer NitroSense software (versions up to and
  including 5.2.62). This allows the attacker to invoke exposed ddsc RPC
  functions, incl…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U'
cwe:
  - CWE-78
  - CWE-306
vendor: Acer
product: NitroSense V5
affected:
  - nitrosense_v5 <= 5.2.62
published: '2026-09-23'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T13:15:28.037'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-50227'
references:
  - url: 'https://community.acer.com/en/kb/articles/20052'
    label: 8fc372e3-d9c5-46e4-9410-38469745c639
tags:
  - nvd
  - cve.org
epss: 0.00348
epssPercentile: 0.25653
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-23T14:50:48.401965Z'
cvssSource: cna
ingestedAt: '2026-09-23T08:20:37.581Z'
---

## Overview

An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket endpoint in Acer NitroSense software (versions up to and including 5.2.62). This allows the attacker to invoke exposed ddsc RPC functions, including child_process.execSync(), resulting in arbitrary command execution in the application context.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
