Skip to content
CodeAuditAgent

CVE-2026-42906

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

Weakness

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

Affected products

  • microsoft windows_10_21h2
  • microsoft windows_10_22h2
  • microsoft windows_11_23h2
  • microsoft windows_11_24h2
  • microsoft windows_11_25h2
  • microsoft windows_11_26h1
  • microsoft windows_server_2022
  • microsoft windows_server_2025

References

Find the bug before an attacker does.

Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.