Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.
[POC] CVE-2026-49176 — CVE-2026-49176_LPE_POC
Local privilege-escalation proof of concept for the Windows WalletService vulnerability fixed in July 2026.
[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-49176_BOF
CVE-2026-49176 WalletService LPE — standalone PoC + Cobalt Strike BOF (SYSTEM command on interactive session)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free