Junglewise Threat Intelligence

CVE-2026-50608: Acer NitroSense authentication bypass in WebSocket handshake

CVE-2026-50608 · Severity: info · Published 2026-09-17

Executive brief

Acer's NitroSense and PredatorSense are system monitoring tools bundled with gaming laptops and desktops. A flaw in the WebSocket authentication process allows unauthorized users to connect to the monitoring service and potentially access system functionality without proper credentials, creating a local privilege escalation or information disclosure risk.

Technical details

The vulnerability is an authentication bypass in the WebSocket handshake process of the Acer System Monitoring component. The service fails to properly validate authentication credentials before accepting WebSocket connections, allowing unauthorized clients to establish connections and interact with service functionality. The attack requires local network access or local system access to reach the WebSocket listener. An attacker with local access can bypass authentication controls, potentially leading to unauthorized command execution or sensitive system data exposure.

Affected products

  • Acer NitroSense <UNKNOWN>
  • Acer PredatorSense <UNKNOWN>

Timeline

  • 2026-09-17: disclosed

References

Related threats