Unauthorized Access Vulnerability in Planet9 Desktop Application by Acer
CVE-2026-50601
6.6MEDIUM
What is CVE-2026-50601?
A significant security flaw in the Planet9 desktop application enables unauthorized access through a hardcoded read-only API key. This vulnerability allows attackers to infiltrate internal repositories, potentially leading to the extraction of sensitive embedded administrative keys and secrets. Such access could enable malicious actors to gain administrative control over repository infrastructure and manipulate source code. To address this vulnerability, Acer has released a critical update designed to resolve the issue and protect users from potential exploitation.
Affected Version(s)
Planet9 desktop application Windows 2.6.131 <= 2.8.124
