Vulnerability Description
Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Windows allows a local user to escalate their privileges to local administrator via direct communication with the LocalAdminService.exe named pipe, bypassing client-side group membership restrictions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Danofficeit | Local Admin Service | 1.2.7.23180 |
Related Weaknesses (CWE)
References
- https://retest.dk/local-privilege-escalation-vulnerability-found-in-local-admin-ExploitThird Party Advisory
- https://www.danofficeit.com/howwedoit/workplace/management/Product
- https://retest.dk/local-privilege-escalation-vulnerability-found-in-local-admin-ExploitThird Party Advisory
FAQ
What is CVE-2026-1680?
CVE-2026-1680 is a vulnerability with a CVSS score of 7.8 (HIGH). Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Windows allows a local user to escalate their privileges to local administrator via...
How severe is CVE-2026-1680?
CVE-2026-1680 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-1680?
Check the references section above for vendor advisories and patch information. Affected products include: Danofficeit Local Admin Service.