Files or Directories Accessible to External Parties in Microsoft Windows and Windows Server - CVE-2026-68831
Published: September 8, 2026
Vulnerability details
The vulnerability allows a local user to disclose file path information.
The vulnerability exists due to files or directories accessible to external parties in the Windows Defender Firewall Service when accessing files or directories associated with the service. A local user can access exposed file system paths to disclose file path information.
Affected software
Windows Server
How to mitigate CVE-2026-68831
Windows Server - addressed in versions 2012 R2 6.3.9600.23397, 2012 6.2.9200.26349, 2016 10.0.14393.9512, 2019 10.0.17763.9245, 2022 10.0.20348.5622, 2025 10.0.26100.33438