Junglewise Threat Intelligence

CVE-2026-20939: Microsoft Windows File Explorer information disclosure

CVE-2026-20939 · Severity: medium · CVSS 5.5 · Published 2026-01-13

Technologies: Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Windows File Explorer, the primary tool used for managing files and folders on Windows computers. An authorized user on a system could exploit this flaw to view sensitive information that they should not have permission to access. This could lead to the unauthorized disclosure of private data or system configuration details, though it requires the attacker to already have local access to the machine.

Technical details

An information disclosure vulnerability (CWE-200) exists in Windows File Explorer due to improper access controls or data handling. An attacker with local access and low-level privileges can exploit this flaw to gain access to sensitive information residing on the system. The attack vector is local, meaning the attacker must be able to execute code or interact with the file system on the target machine. Microsoft has released security updates for various versions of Windows 10, Windows 11, and Windows Server to address this issue. Exploitation does not require user interaction or high privileges, but the impact is limited to confidentiality.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
  • Microsoft Windows Server 2016 All versions

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: advisory

References

Related threats