Unauthorized Access Vulnerability in Planet9 Desktop Application by Acer
CVE-2026-50601

6.6MEDIUM

Key Information:

Vendor

Acer

Vendor
CVE Published:
17 August 2026

What is CVE-2026-50601?

A significant security flaw in the Planet9 desktop application enables unauthorized access through a hardcoded read-only API key. This vulnerability allows attackers to infiltrate internal repositories, potentially leading to the extraction of sensitive embedded administrative keys and secrets. Such access could enable malicious actors to gain administrative control over repository infrastructure and manipulate source code. To address this vulnerability, Acer has released a critical update designed to resolve the issue and protect users from potential exploitation.

Affected Version(s)

Planet9 desktop application Windows 2.6.131 <= 2.8.124

References

CVSS V4

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ayush Choudhary
.