---
id: CVE-2026-50604
title: >-
  A vulnerability has been identified in the Acer Agent Service component
  included with NitroSense and PredatorSense
summary: >-
  A vulnerability has been identified in the Acer Agent Service component
  included with NitroSense and PredatorSense. The socket handshake process does
  not properly require authentication before granting access to the service.
  Under certai…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:U'
cwe:
  - CWE-306
vendor: Acer
product: Agent Service
affected:
  - agent_service <= 1.2.110.2
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T16:25:08.493'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-50604'
references:
  - url: 'https://community.acer.com/en/kb/articles/19871'
    label: 8fc372e3-d9c5-46e4-9410-38469745c639
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T12:52:33.105111Z'
cvssSource: cna
ingestedAt: '2026-09-17T05:11:38.058Z'
epss: 0.00142
epssPercentile: 0.03836
---

## Overview

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially allowing access to functionality that should be restricted.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
