A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned to an application executable used by the Planet9 background service. The service runs with SYSTEM privileges, while the affected executable grants excessive permissions to non-administrative users. As a result, an authenticated local user could potentially modify or replace the executable and execute arbitrary code with SYSTEM privileges when the service starts or the system is restarted.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://community.acer.com/en/kb/articles/19870 |
|
History
Mon, 17 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Acer
Acer planet9 Background Service |
|
| Vendors & Products |
Acer
Acer planet9 Background Service |
Mon, 17 Aug 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned to an application executable used by the Planet9 background service. The service runs with SYSTEM privileges, while the affected executable grants excessive permissions to non-administrative users. As a result, an authenticated local user could potentially modify or replace the executable and execute arbitrary code with SYSTEM privileges when the service starts or the system is restarted. | |
| Title | Planet9 Incorrect Permission Assignment Vulnerability Information | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Acer
Published:
Updated: 2026-08-17T15:55:59.301Z
Reserved: 2026-06-05T07:22:32.054Z
Link: CVE-2026-50602
No data.
Status : Received
Published: 2026-08-17T03:16:50.840
Modified: 2026-08-17T16:16:58.320
Link: CVE-2026-50602
No data.
OpenCVE Enrichment
Updated: 2026-08-17T10:58:06Z