CVE-2026-50602: CWE-732 Incorrect Permission Assignment for Critical Resource in Acer Planet9 background service
CVE-2026-50602 is a high-severity vulnerability in the Acer Planet9 background service caused by incorrect file permissions on an executable. The service runs with SYSTEM privileges, but the executable is writable by non-administrative users. This misconfiguration allows an authenticated local user to modify or replace the executable, potentially leading to arbitrary code execution with SYSTEM privileges upon service start or system reboot.
AI Analysis
Technical Summary
This vulnerability involves incorrect permission assignment (CWE-732) for a critical executable used by the Planet9 background service from Acer. The service operates with SYSTEM-level privileges, but the executable file permissions are overly permissive, allowing non-administrative users to alter the executable. An attacker with local authenticated access could exploit this to execute arbitrary code with SYSTEM privileges when the service restarts or the system reboots. No patch or official remediation has been documented yet, and no known exploits are reported in the wild.
Potential Impact
An authenticated local user can gain SYSTEM-level code execution by modifying or replacing the vulnerable executable. This elevates the user's privileges significantly, potentially compromising the entire system's security. The vulnerability does not require user interaction and has low attack complexity but requires local access with some privileges.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict local user permissions to prevent modification of the executable and consider monitoring for unauthorized changes. Avoid running the service on systems where untrusted users have local access.
CVE-2026-50602: CWE-732 Incorrect Permission Assignment for Critical Resource in Acer Planet9 background service
Description
CVE-2026-50602 is a high-severity vulnerability in the Acer Planet9 background service caused by incorrect file permissions on an executable. The service runs with SYSTEM privileges, but the executable is writable by non-administrative users. This misconfiguration allows an authenticated local user to modify or replace the executable, potentially leading to arbitrary code execution with SYSTEM privileges upon service start or system reboot.
CVSS v4.0
Score 8.5high
Affected software
Acer
Planet9 background service
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves incorrect permission assignment (CWE-732) for a critical executable used by the Planet9 background service from Acer. The service operates with SYSTEM-level privileges, but the executable file permissions are overly permissive, allowing non-administrative users to alter the executable. An attacker with local authenticated access could exploit this to execute arbitrary code with SYSTEM privileges when the service restarts or the system reboots. No patch or official remediation has been documented yet, and no known exploits are reported in the wild.
Potential Impact
An authenticated local user can gain SYSTEM-level code execution by modifying or replacing the vulnerable executable. This elevates the user's privileges significantly, potentially compromising the entire system's security. The vulnerability does not require user interaction and has low attack complexity but requires local access with some privileges.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict local user permissions to prevent modification of the executable and consider monitoring for unauthorized changes. Avoid running the service on systems where untrusted users have local access.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Acer
- Date Reserved
- 2026-06-05T07:22:32.054Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a827161bf8831d5391178d7
Added to database: 08/17/2026, 02:26:41 UTC
Last enriched: 08/24/2026, 13:28:14 UTC
Last updated: 10/01/2026, 05:08:52 UTC
Views: 116
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.