Junglewise Threat Intelligence

CVE-2026-62904: Microsoft Edge incorrect authorization information disclosure

CVE-2026-62904 · Severity: medium · CVSS 5.4 · Published 2026-08-28

Technologies: Microsoft Edge Chromium, Microsoft Edge. Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used by millions of users for accessing the internet. A flaw in its authorization checks allows an attacker to access sensitive information over a network without proper credentials, potentially exposing user data or browser functionality to unauthorized parties.

Technical details

This vulnerability is an incorrect authorization flaw in Microsoft Edge (Chromium-based) that enables information disclosure over a network. An unauthenticated attacker can exploit this by sending crafted network requests to bypass authorization checks and retrieve sensitive information. The attack vector is network-based and does not require user interaction or prior authentication. A patch is expected from Microsoft as part of their security updates.

Affected products

  • Microsoft Edge <UNKNOWN>

Timeline

  • 2026-08-28: disclosed

References

Related threats