A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the PSAdminAgent service, which creates a Named Pipe with a weak Access Control List (ACL). This allows any authenticated local user to connect and send commands. Because the service does not check the caller's privileges before running file deletion commands, a low-privileged local user can exploit this to delete arbitrary files with system authority.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

This issue is resolved in NitroSense versions V3.01.3056.


Workaround

No workaround given by the vendor.

History

Thu, 28 May 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 28 May 2026 03:00:00 +0000

Type Values Removed Values Added
Description A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the PSAdminAgent service, which creates a Named Pipe with a weak Access Control List (ACL). This allows any authenticated local user to connect and send commands. Because the service does not check the caller's privileges before running file deletion commands, a low-privileged local user can exploit this to delete arbitrary files with system authority.
Title NitroSense V3: Security Vulnerability Information
Weaknesses CWE-22
CWE-269
CWE-284
CWE-732
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Acer

Published:

Updated: 2026-05-28T13:12:02.598Z

Reserved: 2026-05-28T02:16:31.420Z

Link: CVE-2026-9789

cve-icon Vulnrichment

Updated: 2026-05-28T13:11:59.272Z

cve-icon NVD

Status : Received

Published: 2026-05-28T03:16:44.200

Modified: 2026-05-28T03:16:44.200

Link: CVE-2026-9789

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-28T04:45:07Z