Junglewise Threat Intelligence

CVE-2026-20823: Microsoft Windows File Explorer information disclosure

CVE-2026-20823 · Severity: medium · CVSS 5.5 · Published 2026-01-13

Technologies: Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A vulnerability in Windows File Explorer could allow an authorized user on a computer to access sensitive information they are not supposed to see. This issue affects various versions of Windows 10, Windows 11, and Windows Server. While an attacker must already have access to the system to exploit this, it could lead to the exposure of private data or system configuration details.

Technical details

An information disclosure vulnerability (CWE-200) exists in Windows File Explorer due to improper handling of sensitive data access. An attacker with local access and low privileges (PR:L) can exploit this flaw to gain access to information that should be restricted. The attack vector is local (AV:L) and requires no user interaction. Microsoft has released security updates to address this issue across affected versions of Windows 10, 11, and Windows Server.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
  • Microsoft Windows Server 2016 All versions

Timeline

  • 2026-01-13: advisory: Initial publication by Microsoft and NVD

References

Related threats