Skip to content
CodeAuditAgent

CVE-2026-48581

Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.

Weakness

Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.

Affected products

  • microsoft surface_go_2_1901_firmware
  • microsoft surface_go_2_1901
  • microsoft surface_go_2_1926_firmware
  • microsoft surface_go_2_1926
  • microsoft surface_go_2_1927_firmware
  • microsoft surface_go_2_1927
  • microsoft surface_go_3_1901_firmware
  • microsoft surface_go_3_1901

References

Find the bug before an attacker does.

Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.