CVE-2026-50434
Analyzed Analyzed - Analysis Complete

Windows Push Notifications Information Disclosure

Vulnerability report for CVE-2026-50434, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-04
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 14 associated CPEs
Vendor Product Version / Range
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50434 is an information disclosure vulnerability in Windows Push Notifications. It allows an authorized attacker with local access to expose sensitive information to an unauthorized actor.

The vulnerability is classified with a CVSS v3.1 BaseScore of 5.5, indicating a medium severity. The vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N means the attack requires local access (AV:L), low attack complexity (AC:L), low privileges (PR:L), no user interaction (UI:N), and has a high impact on confidentiality (C:H) but no impact on integrity or availability.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying this vulnerability on a network or system. Detection may require checking Windows Push Notifications configurations or logs for unauthorized access to sensitive information, but no explicit guidance is available in the given resources.

For precise detection steps, refer to Microsoft's official documentation or security advisories, as they may provide updated tools or scripts for identifying this issue.

Impact Analysis

If exploited, this vulnerability could allow an attacker with local access to your system to disclose sensitive information stored or processed by Windows Push Notifications.

The impact is limited to information disclosure, meaning the attacker could gain access to confidential data but would not be able to modify or delete it. Since the attack requires local access, the risk is higher in environments where multiple users share the same system or where physical security is weak.

Compliance Impact

This vulnerability could potentially affect compliance with data protection regulations depending on the nature of the exposed information.

  • GDPR: If the disclosed information includes personal data of EU citizens, this could be considered a breach of confidentiality, leading to non-compliance with GDPR requirements for data protection and breach notification.
  • HIPAA: If the exposed data includes protected health information (PHI), this could violate HIPAA's Privacy Rule, which requires safeguards to protect the confidentiality of PHI.

Organizations subject to these regulations should assess whether the vulnerability could lead to unauthorized access to regulated data and take appropriate mitigation steps to maintain compliance.

Mitigation Strategies

I don't know

The provided context does not specify immediate mitigation steps for CVE-2026-50434. Typically, for Microsoft vulnerabilities, applying the latest security updates or patches is recommended. Check the linked Microsoft resource for official guidance.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50434. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart