CVE Database
/

CVE-2026-1680

Back to search

CVE-2026-1680

Published: Jan 30, 2026

Modified: Feb 2, 2026

PUBLISHED

Description

Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Windows allows a local user to escalate their privileges to local administrator via direct communication with the LocalAdminService.exe named pipe, bypassing client-side group membership restrictions.

VendorProductVersions

Edgemo (Danoffice IT)

Local Admin Service

affected
1.2.7.23180

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now