AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-61928

MEDIUM · CVSS 5.5 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Windows Hello is vulnerable due to the cleartext storage of sensitive information, which could allow an authorized attacker to tamper with this data locally. The impact includes potential unauthorized access and manipulation of user credentials, posing a risk to system integrity. Organizations utilizing Windows Hello should prioritize addressing this vulnerability to safeguard against local tampering threats.

CVE
CVE-2026-61928
Severity
MEDIUM
CVSS
5.5
EPSS
0.21%
Windows

Original NVD Description

Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.

Related CVEs

Other vulnerabilities affecting the same vendor(s)