CVE-2026-12518
Received Received - Intake

Local Privilege Escalation in Logi Options+ Updater Service

Vulnerability report for CVE-2026-12518, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: Logitech

Description

A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileged local user to execute arbitrary code as SYSTEM.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
logitech logi_options_plus *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-12518 is a local privilege escalation flaw in Logitech Logi Options+ updater service on Windows. It allows a low-privileged user to execute arbitrary code as SYSTEM by exploiting weaknesses in the updater's security boundaries, named pipe access control, and certificate validation.

Detection Guidance

Check for unusual activity in the Logitech Logi Options+ updater service logs or processes. Look for unexpected SYSTEM-level processes spawned by the updater. Review named pipe access logs for unauthorized connections to the updater service.

Impact Analysis

An attacker with local access could gain full SYSTEM privileges, allowing them to install malware, modify system files, or take complete control of the affected machine. No admin rights, user interaction, or network access are required for exploitation.

Mitigation Strategies

Update Logitech Logi Options+ to the latest version immediately. Disable the updater service if not required. Restrict write permissions to directories used by the updater service. Monitor for suspicious SYSTEM-level processes or installations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12518. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart