Junglewise Threat Intelligence

CVE-2026-20834: Microsoft Windows Shell absolute path traversal

CVE-2026-20834 · Severity: medium · CVSS 4.6 · Published 2026-01-13

Technologies: Microsoft Windows 10, Microsoft Windows Server 2008 R2, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A vulnerability in the Windows Shell component could allow an individual with physical access to a computer to view sensitive personal information. By exploiting how the system handles file paths, an attacker could bypass certain restrictions to spoof system elements or access data they should not be able to see. This requires the attacker to be physically present at the device, limiting the risk to lost or unattended hardware.

Technical details

An absolute path traversal vulnerability (CWE-36) exists in the Windows Shell component across multiple versions of Windows and Windows Server. The flaw allows an attacker with physical access to the target machine to manipulate file paths to access restricted information or perform spoofing attacks. According to the vendor, the vulnerability can lead to the exposure of private personal information (CWE-359). The attack vector is strictly physical (AV:P), meaning no remote exploitation is possible. Microsoft has released security updates to address this issue in the affected versions.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
  • Microsoft Windows Server 2008 R2 Service Pack 1

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: advisory

References

Related threats