CVE-2026-50227

6.1

Acer · NitroSense V5

An unauthenticated local attacker can exploit an exposed MQTT broker in Acer NitroSense to achieve arbitrary command execution via RPC functions.

Executive summary

A critical vulnerability in Acer NitroSense V5 allows an unauthenticated local attacker to execute arbitrary commands, posing a significant risk of system compromise.

Vulnerability

The software contains a missing authentication flaw in its MQTT broker, which allows unauthenticated local attackers to access a localhost WebSocket endpoint. This permits the invocation of exposed RPC functions, such as child_process.execSync, leading to OS command injection.

Business impact

Successful exploitation allows an attacker with local access to execute arbitrary commands with the privileges of the NitroSense application. Given the CVSS score of 6.1, this represents a significant risk to system integrity and confidentiality, as an attacker could gain control over the local environment to install malware or exfiltrate sensitive data.

Remediation

Immediate Action: Update the Acer NitroSense software to version 5.2.84 or later immediately to apply the vendor-supplied security patch.

Proactive Monitoring: Monitor system logs for unauthorized attempts to initiate WebSocket connections to local MQTT ports or suspicious child process spawns originating from the NitroSense service.

Compensating Controls: Ensure that local system access is strictly controlled and that only authorized users have the ability to execute applications or interact with local network services on the workstation.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a clear path for local privilege escalation and command execution. It is imperative that all affected systems are updated to version 5.2.84 or later as soon as possible. Administrators should prioritize this update to prevent potential local exploitation of the NitroSense management interface.

More Acer CVEs all →

History

  1. Analyst report written

Sources

Originally found and disclosed by Ayush Choudhary, per the CVE Program record.