Junglewise Threat Intelligence

CVE-2026-20839: Microsoft Windows Client-Side Caching Service improper access control

CVE-2026-20839 · Severity: medium · CVSS 5.5 · Published 2026-01-13

Technologies: Microsoft Windows 10, Microsoft Windows Server 2008 R2, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A vulnerability in the Windows Client-Side Caching (CSC) Service could allow an authorized user to access information they should not be able to see. This service is responsible for making network files available offline; an exploit could lead to the unauthorized disclosure of sensitive local data. To use this flaw, an attacker must already have the ability to log onto the affected system.

Technical details

An improper access control vulnerability (CWE-284) exists in the Windows Client-Side Caching (CSC) Service. The flaw allows a locally authenticated attacker with low privileges to bypass security restrictions and gain unauthorized access to sensitive information stored within the CSC cache. The attack vector is local, meaning the attacker must have existing credentials and the ability to execute code on the target system. Microsoft has released security updates to address this issue across multiple versions of Windows and Windows Server.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
  • Microsoft Windows Server 2008 R2 Service Pack 1

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: advisory

References

Related threats