Junglewise Threat Intelligence

CVE-2026-57980: Microsoft Edge authentication bypass in Chromium engine

CVE-2026-57980 · Severity: medium · CVSS 5.4 · Published 2026-07-17

Technologies: Microsoft Edge (Chromium-based). Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used to access internet and intranet resources. A security flaw allows an attacker to bypass authentication mechanisms, potentially leading to unauthorized data modification or tampering. This could result in a loss of data integrity or the presentation of fraudulent information to the user.

Technical details

This vulnerability is classified as an authentication bypass using an alternate path or channel (CWE-288) within the Chromium-based version of Microsoft Edge. An unauthenticated attacker can exploit this over the network, though user interaction is required for a successful attack. The flaw allows for tampering and unauthorized access to certain data (Low Confidentiality and Low Integrity impact). Microsoft has addressed this in versions 150.0.4078.80 and later.

Affected products

  • Microsoft Edge (Chromium-based) < 150.0.4078.80

Timeline

  • 2026-07-17: disclosed
  • 2026-07-17: advisory

References

Related threats