CyberRota Analysis
AI-GeneratedActive Directory Certificate Services (AD CS) is vulnerable due to the use of externally-controlled format strings, enabling authorized attackers to potentially disclose sensitive information over the network. Organizations utilizing AD CS should prioritize addressing this vulnerability to mitigate the risk of information leakage. This is particularly critical for environments where sensitive data is handled or where compliance with security standards is required.
CVE
CVE-2026-69395
Severity
MEDIUM
CVSS
6.5
EPSS
0.88%
Original NVD Description
Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network.