External Control of File Name or Path in Microsoft Windows and Windows Server - CVE-2026-69383
Published: September 8, 2026
Vulnerability details
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to external control of file name or path in Windows Shell when processing a file name or path. A local user can control a file name or path to elevate privileges.
Successful exploitation depends on environmental factors, system configuration, and additional security measures.
Affected software
Windows Server
How to mitigate CVE-2026-69383
Windows Server - update to 2025 10.0.26100.33438