A security vulnerability has been identified in the Planet9 desktop application where a hardcoded read-only API key permitted unauthorized access to internal repositories. An attacker could exploit this access to extract embedded administrative keys and secrets, potentially allowing them to gain administrative access to repository infrastructure and modify software source code. To mitigate this security risk, Acer has released an update to resolve the issue.
Advisories

No advisories yet.

Fixes

Solution

Planet9 Version v2.8.128 contains a resolution to this vulnerability. The application will automatically update to the patched version (v2.8.128) in the background.


Workaround

No workaround given by the vendor.

History

Mon, 17 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been identified in the Planet9 desktop application where a hardcoded read-only API key permitted unauthorized access to internal repositories. An attacker could exploit this access to extract embedded administrative keys and secrets, potentially allowing them to gain administrative access to repository infrastructure and modify software source code. To mitigate this security risk, Acer has released an update to resolve the issue.
Title Planet9 Hardcoded Credentials Vulnerability Information
Weaknesses CWE-798
References
Metrics cvssV4_0

{'score': 6.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Acer

Published:

Updated: 2026-08-17T02:02:40.508Z

Reserved: 2026-06-05T07:22:32.054Z

Link: CVE-2026-50601

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T03:16:50.703

Modified: 2026-08-17T03:16:50.703

Link: CVE-2026-50601

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T04:00:05Z

Weaknesses