CVE-2026-1680Disclosure(danofficeit / local_admin_service)

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Windows allows a local user to escalate their privileges to local administrator via direct communication with the LocalAdminService.exe named pipe, bypassing client-side group membership restrictions.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-250

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • local_admin_service

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
local_admin_service

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-01-30: 2Technical Details · 2026-01-30: 201-30
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1680 Local Privilege Escalation in Edgemo Local Admin Service via Named Pipe Bypass https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1680

    Post summary

    The text announces the discovery of CVE-2026-1680, a local privilege escalation vulnerability involving a named pipe bypass in Edgemo’s Local Admin Service, without providing PoC, exploit, patch, or active exploitation details.

    0000073
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1680 Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Windows allows a local user to escalate their privi… https://www.cve.org/CVERecord?id=CVE-2026-1680

    Post summary

    CVE-2026-1680 is disclosed as an improper access control flaw in Edgemo’s Local Admin Service, permitting local users to perform privilege escalation via a WCF endpoint.

    00000272
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdanofficeitlocal_admin_service1.2.7.23180windows-

Explore more