#VU121329 Improper access control in Windows and Windows Server - CVE-2026-20839
Published: January 13, 2026
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in Windows Client-Side Caching (CSC) Service. A local user can bypass implemented security restrictions and gain unauthorized access to sensitive information on the system.