EIP-2026-117926

PRE-CVE

SolarWinds Kiwi Syslog Server 8.3.52 - 'Kiwi Syslog Server' Unquoted Service Path

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-117926. PoCs published by Carlos A Garcia R.

AI-analyzed exploit summary This exploit leverages an unquoted service path vulnerability in SolarWinds Kiwi Syslog Server 8.3.52, allowing an attacker to escalate privileges by placing a malicious executable in the root of the C: drive, which gets executed as Local System when the service restarts.

Description

SolarWinds Kiwi Syslog Server 8.3.52 - 'Kiwi Syslog Server' Unquoted Service Path

Exploits (1)

exploitdb WORKING POC
by Carlos A Garcia R · textlocalwindows
https://www.exploit-db.com/exploits/47599

This exploit leverages an unquoted service path vulnerability in SolarWinds Kiwi Syslog Server 8.3.52, allowing an attacker to escalate privileges by placing a malicious executable in the root of the C: drive, which gets executed as Local System when the service restarts.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: SolarWinds Kiwi Syslog Server 8.3.52
Auth required
Prerequisites: Local access to the target system · Ability to write to the root of the C: drive
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026