Junglewise Threat Intelligence

CVE-2026-69403: Microsoft Windows SMB Server missing authorization

CVE-2026-69403 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

Windows SMB Server, a core network file-sharing service on Windows systems, contains a missing authorization vulnerability that allows an authenticated attacker to access sensitive information they should not be able to reach. This could expose confidential data stored on network shares to unauthorized local users.

Technical details

The vulnerability is a missing authorization flaw in Windows SMB Server that fails to properly enforce access controls. An authorized local attacker can exploit this to read or access data that should be restricted, resulting in information disclosure. The vulnerability requires the attacker to already have valid credentials or local access. No public exploits have been reported. Microsoft has released patches available through the MSRC Security Update Guide.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats