Inclusion of Sensitive Information in Log Files in Microsoft Windows and Windows Server - CVE-2026-68873
Published: September 8, 2026
Vulnerability details
The vulnerability allows a local user to disclose information.
The vulnerability exists due to insertion of sensitive information into log files in Windows Program Compatibility Assistant Service when logging sensitive information. A local user can access log files containing sensitive information to disclose information.
The disclosed information may include uninitialized heap memory.
Affected software
Windows Server
How to mitigate CVE-2026-68873
Windows Server - update to 2025 10.0.26100.33438