SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-49170

HIGH · CVSS 7.8 EPSS 2.80%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

The vulnerability in the Windows StateRepository API allows an authorized attacker to exploit insufficient access control, enabling local privilege escalation. This can lead to unauthorized access to sensitive system resources and potentially compromise the integrity of the system. Organizations using affected Windows products should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-49170
Severity
HIGH
CVSS
7.8
EPSS
2.80%
Windows

Original NVD Description

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

Related CVEs

Other vulnerabilities affecting the same vendor(s)