Skip to main content
EPSS 0.1%top 97%

CVE-2026-50602: CWE-732 Incorrect Permission Assignment for Critical Resource in Acer Planet9 background service

0
High
VulnerabilityCVE-2026-50602cvecve-2026-50602cwe-732
Published: 08/17/2026 (08/17/2026, 02:16:49 UTC)
Source: CVE Database V5
Vendor/Project: Acer
Product: Planet9 background service

Description

CVE-2026-50602 is a high-severity vulnerability in the Acer Planet9 background service caused by incorrect file permissions on an executable. The service runs with SYSTEM privileges, but the executable is writable by non-administrative users. This misconfiguration allows an authenticated local user to modify or replace the executable, potentially leading to arbitrary code execution with SYSTEM privileges upon service start or system reboot.

CVSS v4.0

Score 8.5high

Attack Vector
Local
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected software

Acer

Planet9 background service

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/24/2026, 13:28:14 UTC

Technical Analysis

This vulnerability involves incorrect permission assignment (CWE-732) for a critical executable used by the Planet9 background service from Acer. The service operates with SYSTEM-level privileges, but the executable file permissions are overly permissive, allowing non-administrative users to alter the executable. An attacker with local authenticated access could exploit this to execute arbitrary code with SYSTEM privileges when the service restarts or the system reboots. No patch or official remediation has been documented yet, and no known exploits are reported in the wild.

Potential Impact

An authenticated local user can gain SYSTEM-level code execution by modifying or replacing the vulnerable executable. This elevates the user's privileges significantly, potentially compromising the entire system's security. The vulnerability does not require user interaction and has low attack complexity but requires local access with some privileges.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict local user permissions to prevent modification of the executable and consider monitoring for unauthorized changes. Avoid running the service on systems where untrusted users have local access.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
Acer
Date Reserved
2026-06-05T07:22:32.054Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6a827161bf8831d5391178d7

Added to database: 08/17/2026, 02:26:41 UTC

Last enriched: 08/24/2026, 13:28:14 UTC

Last updated: 10/01/2026, 05:08:52 UTC

Views: 116

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses