Cleartext storage of sensitive information in Microsoft Windows and Windows Server - CVE-2026-61928
Published: August 12, 2026
Vulnerability details
The vulnerability allows a local user to perform tampering.
The vulnerability exists due to cleartext storage of sensitive information in Windows Hello when storing sensitive information locally. A local user can access improperly protected data to perform tampering.
This could allow unauthorized modifications to protected system data and alter system state or configuration beyond normal privileges.
Affected software
Windows Server
How to mitigate CVE-2026-61928
Windows Server - addressed in versions 2016 10.0.14393.9418, 2019 10.0.17763.9115, 2022 10.0.20348.5440, 2022 10.0.20348.5499, 2025 10.0.26100.33222, 2025 10.0.26100.33296