Junglewise Threat Intelligence

CVE-2026-69267: Microsoft Windows Connected User Experiences and Telemetry access control bypass

CVE-2026-69267 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Connected User Experiences and Telemetry is a Microsoft service that collects diagnostic and usage data from Windows systems. A flaw in access controls allows an authorized local user to access sensitive telemetry information they should not have permission to view, potentially exposing personal or system configuration details.

Technical details

This vulnerability is an insufficient granularity of access control (privilege escalation / authorization bypass) in the Windows Connected User Experiences and Telemetry service. The root cause is inadequate permission checks that fail to properly restrict which local users can access specific telemetry data. An authenticated local attacker can bypass access controls to read sensitive information that should be restricted. The attack requires local system access and existing user authentication. No privilege elevation to SYSTEM or admin is required. The vulnerability enables information disclosure of confidential telemetry and system configuration data, though it does not allow modification or service disruption.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats