EIP-2026-117676

PRE-CVE

NetDrive 2.6.12 - Unquoted Service Path Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-117676. PoCs published by Tulpa.

AI-analyzed exploit summary This is a technical writeup detailing an unquoted service path vulnerability in NetDrive 2.6.12, which could allow local privilege escalation (LPE) due to improper handling of the service executable path. The analysis includes service configuration details and exploitation prerequisites.

Description

NetDrive 2.6.12 - Unquoted Service Path Privilege Escalation

Exploits (1)

exploitdb WRITEUP
by Tulpa · textlocalwindows
https://www.exploit-db.com/exploits/40422

This is a technical writeup detailing an unquoted service path vulnerability in NetDrive 2.6.12, which could allow local privilege escalation (LPE) due to improper handling of the service executable path. The analysis includes service configuration details and exploitation prerequisites.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Theoretical
Target: NetDrive 2.6.12
Auth required
Prerequisites: Local access to the system · Ability to write to the system root path
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026