5.5
CVE-2026-26123
- EPSS 0.04%
- Veröffentlicht 10.03.2026 19:01:31
- Zuletzt bearbeitet 13.03.2026 20:45:13
- Quelle secure@microsoft.com
- CVE-Watchlists
- Unerledigt
Microsoft Authenticator Information Disclosure Vulnerability
Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Authenticator SwPlatformiphone_os Version < 6.8.40
Microsoft ≫ Authenticator SwPlatformandroid Version < 6.2511.7533
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.134 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| secure@microsoft.com | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
CWE-939 Improper Authorization in Handler for Custom URL Scheme
The product uses a handler for a custom URL scheme, but it does not properly restrict which actors can invoke the handler using the scheme.