Junglewise Threat Intelligence

CVE-2026-50601: Acer Planet9 hardcoded API key exposure

CVE-2026-50601 · Severity: info · Published 2026-08-17

Vendors: Acer.

Executive brief

Planet9 is a desktop application that manages access to internal repositories. A hardcoded read-only API key embedded in the application allows attackers to access internal repositories and extract additional credentials, potentially leading to unauthorized administrative access and the ability to modify source code stored in repositories.

Technical details

The vulnerability involves a hardcoded read-only API key embedded in the Planet9 desktop application's code. An attacker with access to the application binary can extract this key and use it to authenticate to internal repository infrastructure. Once authenticated, an attacker can enumerate repositories and extract additional embedded secrets and administrative credentials, leading to privilege escalation and unauthorized code modification. The attack requires possession of the application binary but no network reconnaissance or user interaction. Acer has released an update to remove the hardcoded key and remediate the issue.

Affected products

  • Acer Planet9 <UNKNOWN>

Timeline

  • 2026-08-17: disclosed
  • patched: Update released by Acer to remove hardcoded API key

References

Related threats