EIP-2026-117901

PRE-CVE

SentryHD 02.01.12e - Local Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-117901. PoCs published by Kacper Szurek.

AI-analyzed exploit summary This exploit leverages a privilege escalation vulnerability in SentryHD 02.01.12e by reading plaintext credentials from a configuration file and abusing a scheduled shutdown feature to execute arbitrary commands as SYSTEM. It creates a new administrative user via a batch file executed during a scheduled shutdown.

Description

SentryHD 02.01.12e - Local Privilege Escalation

Exploits (1)

exploitdb WORKING POC VERIFIED
by Kacper Szurek · pythonlocalwindows
https://www.exploit-db.com/exploits/41090

This exploit leverages a privilege escalation vulnerability in SentryHD 02.01.12e by reading plaintext credentials from a configuration file and abusing a scheduled shutdown feature to execute arbitrary commands as SYSTEM. It creates a new administrative user via a batch file executed during a scheduled shutdown.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: SentryHD 02.01.12e
No auth needed
Prerequisites: Local access to the system · SentryHD 02.01.12e installed with default configurations · UPSMan service running as SYSTEM
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026