Junglewise Threat Intelligence

CVE-2026-69822: Microsoft Windows Kerberos numeric truncation privilege escalation

CVE-2026-69822 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Kerberos is the authentication system that controls user login and access to corporate networks and systems. A numeric truncation error in this system allows an attacker who already has local access or valid credentials to escalate their privileges to higher levels of system access, potentially gaining administrative control.

Technical details

The vulnerability is a numeric truncation error in the Windows Kerberos authentication subsystem. An authorized attacker with local access or valid credentials can exploit this flaw to elevate their privileges on the affected system. The attack requires prior authentication or local access (precondition: attacker must already have some level of system access). The vulnerability allows privilege escalation from a lower-privilege account to a higher-privilege level. A patch from Microsoft is expected to address this issue.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats