Junglewise Threat Intelligence

CVE-2026-12518: Logitech Logi Options+ privilege escalation in updater service

CVE-2026-12518 · Severity: info · CVSS 8.8 · Published 2026-09-14

Executive brief

Logi Options+ is a device configuration and management utility for Logitech peripherals on Windows. A vulnerability in its background updater service allows a low-privileged local user to execute code with SYSTEM (administrator) privileges, potentially enabling malware installation, credential theft, or complete system compromise.

Technical details

This is a local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows. A low-privileged local user can exploit a flaw in the updater service to execute arbitrary code with SYSTEM-level privileges. The attack requires local access to the affected system but does not require authentication or network reachability. Successful exploitation grants complete system control, enabling an attacker to install malware, access sensitive data, or compromise the entire system.

Affected products

  • Logitech Logi Options+ <UNKNOWN>

Timeline

  • 2026-09-14: disclosed

References