CVE-2026-12518: Local privilege escalation in the Logi Options+ updater service on Windows
Published Sep 14, 2026
·Updated
A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileged local user to execute arbitrary code as SYSTEM.
Affected Software
1 affected component
Logitech Logi Options+
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Logitech Logi Options+to a version that resolves this vulnerability.Fixed in 2.7
Event History
Sep 14, 2026
CVE Published
via MITRE·07:27 AM
Data Sourced
via MITRE·07:27 AM
RemedyDescriptionWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
A low-privileged local user on Windows can exploit it. The issue is in the Logitech Logi Options+ updater service and can result in arbitrary code execution as SYSTEM.
2
What level of access is required before exploitation?
The attacker must already have local access as a low-privileged user. The provided information does not indicate that it can be exploited remotely.