Skip to content
October 5, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Windows
  • A Simple New Windows 11 Local Account Bypass Appears
  • Windows

A Simple New Windows 11 Local Account Bypass Appears

Do Son September 14, 2026 2 minutes read
0
Windows 11 Home OOBE local account bypass using the Learn More hyperlink on the sign-in screen
Add Daily CyberSecurity as a preferred source on Google

The well-known enthusiast BobPony recently uncovered a new way to circumvent account sign-in on Windows 11 Home. The method proves remarkably simple yet effective. Thereafter, when users installing the system encounter the point in the OOBE interface that forces a Microsoft account login, they can employ this trick to swiftly create a local account.

The Current Flow Demands a Microsoft Account

At present, Windows 11 Home compels users to register and log in with a Microsoft account. The methods once used to skip account sign-in, including OOBE\BYPASSNRO, editing the registry, or invoking start ms-cxh:localonly, have all been progressively removed by Microsoft. Consequently, users can no longer create a local account through the ordinary route.

Attempting to bypass the login with a bogus account such as no@thankyou.com is likewise futile. Naturally, these are all evasion methods that Microsoft has successively deleted across version updates. Therefore, users wishing to bypass account sign-in have found the task relatively troublesome.

The New Bypass Is Exceedingly Simple

On the screen where one enters an account, a lengthy block of Microsoft’s explanatory text sits below, and within it lies a Learn More hyperlink. Users need only click that link, whereupon the details load and the setup then automatically jumps to the create-a-local-account page. BobPony shared the discovery in a post demonstrating the Learn More trick on the Microsoft account sign-in page.

This appears to be some kind of bug. Under normal circumstances, OOBE itself fetches content online, and the Learn More hyperlink ought to display additional information before offering a return button. In reality, however, it leaps directly to the create-a-local-account page, so this is almost certainly an error.

The Bad News for Users

The unfortunate part is that if Microsoft intends to seal off this method, doing so is trivially easy. It need only continue adjusting the OOBE backend server to quickly close the link-redirection error. In that event, users would once again be forced to log in with a Microsoft account, unable to create a local one.

Related coverage

  • Windows 11 Insider Apps Get Major Updates
  • New Windows 11 Tools: Point-in-Time Restore & Network-Enabled Recovery Environment
  • Goodbye Lag: Microsoft’s “Windows K2” Project to Rebuild the Start Menu for Instant Speed
  • Resolve Microsoft Excel Copy Paste Issues Now
  • Windows Backup Gets Upgrade: Microsoft Testing Seamless Data Migration to New PCs
  • The End of Offline Era: Microsoft Kills Phone Activation After 24 Years
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our tech and OS security coverage helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: BobPony Local Account Microsoft Microsoft Account OOBE Windows 11

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-103510CVSS 9.5
    P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank. In affected...
    📅 Updated: Oct 5, 2026
  • CVE-2026-100102CVSS 9.5
    Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An attacker with network access to...
    📅 Updated: Oct 5, 2026
  • CVE-2026-100103CVSS 10.0
    Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default...
    📅 Updated: Oct 5, 2026
  • CVE-2026-8763CVSS 9.3
    In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This...
    📅 Updated: Oct 5, 2026
  • CVE-2026-105223CVSS 9.1
    maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data,...
    📅 Updated: Oct 5, 2026
  • CVE-2026-105216CVSS 9.1
    go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the...
    📅 Updated: Oct 5, 2026
  • CVE-2026-105222CVSS 9.1
    The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer...
    📅 Updated: Oct 5, 2026
  • CVE-2026-105294CVSS 9.1
    Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write...
    📅 Updated: Oct 5, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.