---
id: CVE-2026-8069
title: >-
  PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege
  Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that
  uses a custom protocol to invoke internal functions
summary: >-
  PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege
  Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that
  uses a custom protocol to invoke internal functions. However, this Named Pipe
  is misconfigu…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
  - CWE-269
  - CWE-284
  - CWE-732
vendor: acer
product: nitrosense
affected:
  - 'nitrosense >= 3.00.0000, < 3.01.3056'
  - 'predatorsense >= 3.00.0000, < 3.00.3198'
patched:
  - nitrosense 3.01.3056
  - predatorsense 3.00.3198
published: '2026-05-08'
updated: '2026-08-12'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8069'
references:
  - url: 'https://community.acer.com/en/kb/articles/19652'
    label: 8fc372e3-d9c5-46e4-9410-38469745c639
tags:
  - nvd
  - exploit-available
epss: 0.0012
epssPercentile: 0.02094
ingestedAt: '2026-08-13T13:03:06.291Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/S1eezer/CVE-2026-8069'
  checkedAt: '2026-09-24T07:53:18.912Z'
exploitAvailable: true
---

## Overview

PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY\SYSTEM privileges and to delete arbitrary files with SYSTEM privileges. By leveraging this, an attacker can execute arbitrary code on the target system with elevated privileges.

## Affected

- `nitrosense >= 3.00.0000, < 3.01.3056`
- `predatorsense >= 3.00.0000, < 3.00.3198`

## Remediation

Upgrade past the affected range:

- `nitrosense 3.01.3056`
- `predatorsense 3.00.3198`
