Arbitrary Command Execution Flaw in Acer NitroSense Software
CVE-2026-50227
6.1MEDIUM
What is CVE-2026-50227?
A critical security flaw exists in the Acer NitroSense software, up to version 5.2.62, that allows unauthenticated local attackers to connect to the MQTT broker over its localhost WebSocket endpoint. By leveraging this access, attackers can invoke exposed ddsc RPC functions, including child_process.execSync(), leading to arbitrary command execution within the application's context. This vulnerability poses significant risks as it can potentially allow malicious actors to execute arbitrary commands, compromising the system's integrity.
Affected Version(s)
NitroSense V5 Windows * <= 5.2.62
