CVE-2026-8069 is a local privilege escalation vulnerability affecting Acer PredatorSense versions 3.00.3136 through 3.00.3196. The flaw is caused by a misconfigured Windows Named Pipe exposed by the application. That pipe implements a custom protocol used to invoke internal functions, but its access controls are insufficiently restricted, allowing any authenticated local user to interact with privileged functionality. Successful exploitation enables arbitrary code execution in the context of NT AUTHORITY\SYSTEM and also permits deletion of arbitrary files with SYSTEM privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This four-file repository contains a research write-up, separate CC-BY/MIT licensing, and one Windows Python proof of concept: `poc/acer_cve_2026_8069_poc.py`. The PoC targets CVE-2026-8069 in Acer's LocalSystem PSSvc service used by NitroSense and PredatorSense. It uses ctypes bindings for Windows named-pipe APIs to contact `\\.\pipe\predatorsense_service_namedpipe`, optionally prints a recovered dispatcher command map, or performs an execution validation through dispatcher command 0x07. The vulnerable service checks whether a supplied executable path merely contains/starts with its service directory rather than resolving and enforcing canonical path containment. A path prefixed with the allowed directory and containing `..\` segments passes the check while resolving to a different executable, such as cmd.exe in System32. Command mode 0x72 makes PSSvc duplicate the SYSTEM token of winlogon.exe and create the requested process with CreateProcessAsUserW. This is a functioning local privilege-escalation PoC, not merely a detector: a standard local user can launch a SYSTEM process without user interaction. The command map also indicates that the pipe dispatcher exposes privileged registry, WMI, hardware, and service-related functions, though the implemented exploitation path focuses on SYSTEM process creation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.