Junglewise Threat Intelligence

CVE-2026-8069: Acer PredatorSense privilege escalation in Windows Named Pipe

CVE-2026-8069 · Severity: high · CVSS 7.8 · Published 2026-05-08

Technologies: Acer Predatorsense, Acer NitroSense. Vendors: Acer.

Executive brief

PredatorSense is system monitoring and management software used by Acer computer owners. A misconfigured Windows Named Pipe in versions 3.00.3136 to 3.00.3196 allows any authenticated local user to execute arbitrary code and delete files with system-level privileges, enabling attackers to take complete control of affected machines.

Technical details

The vulnerability is a privilege escalation flaw in PredatorSense's Windows Named Pipe communication channel. The Named Pipe implements a custom protocol to invoke internal functions but lacks proper access control validation, allowing any authenticated local user to send arbitrary commands. An attacker with local access can exploit this to execute code with NT AUTHORITY\SYSTEM privileges or delete arbitrary files with system permissions. The attack requires local authentication but no elevated privileges at the outset; remote exploitation is not possible. Patches are available in versions after 3.00.3196.

Affected products

  • Acer PredatorSense 3.00.3136 to 3.00.3196

Timeline

  • 2026-05-08: disclosed: CVE-2026-8069 published
  • 2026-05-08: other: Vulnerability affecting PredatorSense 3.00.3136 through 3.00.3196

References

Related threats