Path traversal in Microsoft Windows and Windows Server - CVE-2026-50454
Published: July 17, 2026
Vulnerability details
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to relative path traversal in Windows User Interface Core when handling local file paths. A local user can manipulate path input to elevate privileges.
Successful exploitation could allow deletion of arbitrary system files and lead to SYSTEM privileges.
Affected software
Windows Server
How to mitigate CVE-2026-50454
Windows Server - addressed in versions 2012 R2 6.3.9600.23291, 2025 10.0.26100.33158