Arbitrary Command Execution Flaw in Acer NitroSense Software
CVE-2026-50227

6.1MEDIUM

Key Information:

Vendor

Acer

Vendor
CVE Published:
23 September 2026

What is CVE-2026-50227?

A critical security flaw exists in the Acer NitroSense software, up to version 5.2.62, that allows unauthenticated local attackers to connect to the MQTT broker over its localhost WebSocket endpoint. By leveraging this access, attackers can invoke exposed ddsc RPC functions, including child_process.execSync(), leading to arbitrary command execution within the application's context. This vulnerability poses significant risks as it can potentially allow malicious actors to execute arbitrary commands, compromising the system's integrity.

Affected Version(s)

NitroSense V5 Windows * <= 5.2.62

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ayush Choudhary
.