Junglewise Threat Intelligence

CVE-2026-50227: Acer NitroSense MQTT broker authentication bypass

CVE-2026-50227 · Severity: info · Published 2026-09-23

Technologies: Acer NitroSense. Vendors: Acer.

Executive brief

Acer NitroSense is a gaming system control application that manages hardware settings on gaming laptops. An attacker with local access can connect to an unauthenticated MQTT message broker and execute arbitrary commands with the application's privileges, potentially allowing full control over the system.

Technical details

An MQTT broker in NitroSense listens on localhost over WebSocket without requiring authentication, allowing unauthenticated local attackers to connect and invoke exposed DDSC RPC functions including child_process.execSync(). This results in arbitrary code execution in the NitroSense application context. The vulnerability affects versions up to and including 5.2.62.

Affected products

  • Acer NitroSense up to and including 5.2.62

Timeline

  • 2026-09-23: disclosed

References

Related threats