Junglewise Threat Intelligence

CVE-2026-66317: Microsoft Edge origin validation error allows network tampering

CVE-2026-66317 · Severity: medium · CVSS 5.4 · Published 2026-08-04

Technologies: Microsoft Edge Chromium, Microsoft Edge. Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used by millions of users to access online services and websites. An origin validation flaw allows an attacker on the network to tamper with data in transit or inject malicious content into web pages, potentially compromising user sessions, stealing credentials, or delivering malware.

Technical details

The vulnerability is an origin validation error in Microsoft Edge's Chromium-based implementation. An attacker on the network (adjacent or local network position) can bypass origin checks to perform tampering attacks over HTTP/network protocols. The flaw allows injection or modification of web content without proper cross-origin protections. This typically requires network-level access but does not require user authentication or browser privileges. No patch information is publicly available at this time based on the advisory content provided.

Affected products

  • Microsoft Edge <UNKNOWN>

Timeline

  • 2026-08-04: disclosed

References

Related threats