CVE-2026-20818

MEDIUM

Windows Kernel - Info Disclosure

Title source: llm
STIX 2.1

Description

Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally.

Scores

CVSS v3 6.2
EPSS 0.0004
EPSS Percentile 12.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (13)
Microsoft/Windows Server 2016 10.0.14393.0 - 10.0.14393.8783
Microsoft/Windows Server 2016 (Server Core installation) 10.0.14393.0 - 10.0.14393.8783
Microsoft/Windows Server 2019 10.0.17763.0 - 10.0.17763.8276
Microsoft/Windows Server 2019 (Server Core installation) 10.0.17763.0 - 10.0.17763.8276
Microsoft/Windows Server 2022 10.0.20348.0 - 10.0.20348.4648
Microsoft/Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.0 - 10.0.25398.2092
Microsoft/Windows Server 2025 10.0.26100.0 - 10.0.26100.32230
Microsoft/Windows Server 2025 (Server Core installation) 10.0.26100.0 - 10.0.26100.32230
microsoft/windows_server_2016 < 10.0.14393.8783
microsoft/windows_server_2019 < 10.0.17763.8276
... and 3 more
Published Jan 13, 2026
Tracked Since Feb 18, 2026