Junglewise Threat Intelligence

CVE-2026-69453: Microsoft Windows Search Component missing authorization

CVE-2026-69453 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Search is a system component that indexes and searches files on Windows computers. A missing authorization check allows an authenticated local attacker to tamper with the search component's operations, potentially affecting search functionality or system stability.

Technical details

The Windows Search Component lacks proper authorization validation, allowing authenticated local attackers to perform tampering operations. The vulnerability requires local access and prior authentication, limiting its attack surface. No remote exploitation is possible.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats