Improper access control in Microsoft Edge - CVE-2026-58286

 

Improper access control in Microsoft Edge - CVE-2026-58286

Published: July 17, 2026


Vulnerability identifier: #VU138359
CSH Severity: High
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58286
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing and disclose sensitive information.

The vulnerability exists due to improper access control in Microsoft Edge (Chromium-based) when rendering attacker-controlled web content. A remote attacker can host a specially crafted website with deceptive or invisible form elements to perform spoofing and disclose sensitive information.

Successful exploitation requires crafting deceptive or invisible form elements and the user to perform two sequential taps. Malicious JavaScript code can read information in the victim's browser associated with the vulnerable URL.


Affected software

Microsoft Edge

How to mitigate CVE-2026-58286

Install security update from vendor's website.

Microsoft Edge - update to 150.0.4078.48

External References

Related Security Bulletins