CVE-2026-1680

Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Windows allows a local user to escalate their privileges to local administrator via direct communication with the LocalAdminService.exe named pipe, bypassing client-side group membership restrictions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:danofficeit:local_admin_service:1.2.7.23180:*:*:*:*:windows:*:*

History

No history.

Information

Published : 2026-01-30 07:16

Updated : 2026-03-03 15:06


NVD link : CVE-2026-1680

Mitre link : CVE-2026-1680

CVE.ORG link : CVE-2026-1680


JSON object : View

Products Affected

danofficeit

  • local_admin_service
CWE
CWE-250

Execution with Unnecessary Privileges

NVD-CWE-Other