Executive brief
Planet9 is a desktop application that manages access to internal repositories. A hardcoded read-only API key embedded in the application allows attackers to access internal repositories and extract additional credentials, potentially leading to unauthorized administrative access and the ability to modify source code stored in repositories.
Technical details
The vulnerability involves a hardcoded read-only API key embedded in the Planet9 desktop application's code. An attacker with access to the application binary can extract this key and use it to authenticate to internal repository infrastructure. Once authenticated, an attacker can enumerate repositories and extract additional embedded secrets and administrative credentials, leading to privilege escalation and unauthorized code modification. The attack requires possession of the application binary but no network reconnaissance or user interaction. Acer has released an update to remove the hardcoded key and remediate the issue.
Affected products
- Acer Planet9 <UNKNOWN>
Timeline
- 2026-08-17: disclosed
- patched: Update released by Acer to remove hardcoded API key