Missing Authentication for Critical Function in Microsoft Windows and Windows Server - CVE-2026-83991
Published: September 9, 2026
Vulnerability details
The vulnerability allows a local user to make unauthorized modifications to protected system data.
The vulnerability exists due to missing authentication for critical function in Windows Cloud Files Mini Filter Driver when invoking critical functions. A local user can invoke critical functions without authentication to make unauthorized modifications to protected system data.
Affected software
Windows Server
How to mitigate CVE-2026-83991
Windows Server - addressed in versions 2019 10.0.17763.9245, 2022 10.0.20348.5622, 2025 10.0.26100.33438