CVE-2026-50603 MEDIUM

CVE-2026-50603: Hard-coded encryption key vulnerability in Acer Agent Service for NitroSense and PredatorSense

Vendor Acer
Product Agent Service
Weakness CWE-321
Published September 17, 2026
Last update September 17, 2026

CVSS base score

4.9/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:U

What the vulnerability does

01Description

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions.

Key dates

02Disclosure timeline

September 17, 2026 CVE published
September 17, 2026 Record updated

Related vulnerabilities

04Related CVE