CVE-2026-50389
Analyzed Analyzed - Analysis Complete

Sensitive Information Exposure in Windows File Explorer

Vulnerability report for CVE-2026-50389, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 20 associated CPEs
Vendor Product Version / Range
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_server_2016 to 10.0.14393.9339 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50389 is a vulnerability in Windows File Explorer that involves the exposure of sensitive information to an unauthorized actor. This means that an attacker who is already authorized on the system (has local access) can exploit this flaw to disclose sensitive information stored or accessible through Windows File Explorer.

The vulnerability is classified as an information disclosure issue, where the attacker does not need to perform complex actions to exploit it. The CVSS v3.1 score of 5.5 indicates a medium severity, with the attack vector being local (AV:L), low attack complexity (AC:L), and requiring low privileges (PR:L). The impact is limited to confidentiality (C:H), meaning the attacker can access high-confidentiality data but cannot modify it or disrupt availability.

Detection Guidance

The provided context does not specify methods or commands to detect this vulnerability on a network or system. Detection typically involves checking for unusual access patterns or verifying if sensitive information is exposed through Windows File Explorer, but no specific tools or commands are mentioned.

To detect potential exposure, you may need to audit file access logs or use Microsoft-provided tools for vulnerability assessment, but the context does not provide explicit instructions.

Impact Analysis

This vulnerability can impact you in several ways if you are using a system with Windows File Explorer affected by CVE-2026-50389.

  • An attacker with local access to your system could exploit this flaw to access sensitive information stored in or accessible through Windows File Explorer. This could include files, documents, or other data that you may not intend to share.
  • The disclosed information could be used for further attacks, such as identity theft, corporate espionage, or unauthorized access to other systems or accounts if the exposed data includes credentials or personal details.
  • If you are part of an organization, this vulnerability could lead to a breach of internal data, potentially exposing proprietary or confidential business information.
Compliance Impact

This vulnerability can have implications for compliance with various standards and regulations, depending on the nature of the exposed data and the context in which it is used.

  • GDPR (General Data Protection Regulation): If the exposed information includes personal data of EU citizens, this vulnerability could lead to a breach of GDPR requirements. Organizations are required to protect personal data from unauthorized access, and failure to do so could result in significant fines and legal consequences.
  • HIPAA (Health Insurance Portability and Accountability Act): If the exposed data includes protected health information (PHI), this vulnerability could result in a HIPAA violation. Covered entities and business associates must ensure the confidentiality, integrity, and availability of PHI, and unauthorized disclosure could lead to penalties.
  • Other standards, such as PCI DSS (Payment Card Industry Data Security Standard), may also be impacted if the exposed data includes payment card information. Non-compliance with these standards can result in fines, loss of certification, or other legal actions.

Organizations should assess the types of data accessible through Windows File Explorer and determine if exploitation of this vulnerability could lead to non-compliance with applicable regulations. Mitigation measures, such as applying patches or implementing additional access controls, may be necessary to maintain compliance.

Mitigation Strategies

The provided context does not include specific mitigation steps for CVE-2026-50389. However, general best practices for mitigating information disclosure vulnerabilities in Windows File Explorer may include:

  • Apply the latest security updates from Microsoft as soon as they are available. Check the Microsoft Update Guide for patches related to this CVE.
  • Restrict local access to sensitive files and directories to authorized users only.
  • Monitor for unusual file access patterns or unauthorized attempts to access sensitive information.
  • Review and enforce least-privilege access controls to minimize the risk of unauthorized information disclosure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50389. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart