Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-50602— Planet9 Incorrect Permission Assignment Vulnerability Information

Quick assessment

Affected
Acer Planet9 background service
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Acer Planet9是中国Acer公司的一个后台服务程序。 Acer Planet9存在权限许可和访问控制问题漏洞,该漏洞源于文件权限分配不当,其后台服务使用的可执行文件向非管理用户授予过多权限,可能导致经过身份验证的本地用户在服务启动或系统重启时修改或替换该可执行文件,并以SYSTEM权限执行任意代码。

CVSS 8.5 · High EPSS 0.14% · P3

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 1

VendorProduct Version RangeStatus
Acer Planet9 background service NA affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-50602

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Planet9 Incorrect Permission Assignment Vulnerability Information
Source: CVE Program / CVE List V5
Vulnerability Description
A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned to an application executable used by the Planet9 background service. The service runs with SYSTEM privileges, while the affected executable grants excessive permissions to non-administrative users. As a result, an authenticated local user could potentially modify or replace the executable and execute arbitrary code with SYSTEM privileges when the service starts or the system is restarted.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
关键资源的不正确权限授予
Source: CVE Program / CVE List V5
Vulnerability Title
Acer Planet9 权限许可和访问控制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Acer Planet9是中国Acer公司的一个后台服务程序。 Acer Planet9存在权限许可和访问控制问题漏洞,该漏洞源于文件权限分配不当,其后台服务使用的可执行文件向非管理用户授予过多权限,可能导致经过身份验证的本地用户在服务启动或系统重启时修改或替换该可执行文件,并以SYSTEM权限执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Acer Planet9 background service NA -

II. Public POCs for CVE-2026-50602

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-50602

请登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2026-50602

No comments yet


Leave a comment