Weak Authentication in Microsoft Windows and Windows Server - CVE-2026-59135
Published: August 12, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to weak authentication in Microsoft Windows Search Component when handling local access to search functionality. A local user can access the component with insufficient authentication checks to disclose sensitive information.
The disclosed information includes file path information from the file system.
Affected software
Windows Server
How to mitigate CVE-2026-59135
Windows Server - addressed in versions 2012 R2 6.3.9600.23337, 2012 6.2.9200.26279, 2016 10.0.14393.9418, 2019 10.0.17763.9115, 2022 10.0.20348.5440, 2022 10.0.20348.5499, 2025 10.0.26100.33222, 2025 10.0.26100.33296