Main
Vulnerability Database
Exploits
ID:12735 - Exploit for Improper Authentication in Windows and Windows Server - CVE-2026-26128
ID:12735 - Exploit for Improper Authentication in Windows and Windows Server - CVE-2026-26128
Published: May 22, 2026
Vulnerability identifier: #VU123691
Vulnerability risk: Low
CVE-ID: CVE-2026-26128
CWE-ID: CWE-287
Exploitation vector: Local access
Vulnerable software:
Windows
Windows Server
Windows
Windows Server
Link to public exploit:
Vulnerability description
The vulnerability allows a local user to bypass authentication process.
The vulnerability exists due to an error when processing authentication requests in Windows SMB Server. A local user can bypass authentication process and gain unauthorized access to the application.
Remediation
Install updates from vendor's website.