CVE-2021-31936 is an information disclosure vulnerability affecting Microsoft Accessibility Insights for Web. With a CVSS score of 7.4 (High), it can be exploited remotely with low attack complexity, requiring user interaction to disclose sensitive information. While the vulnerability is not listed in CISA's KEV catalog and no public exploit code exists, it received limited community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.26.0CPE matchmatch criteria | cpe:2.3:a:microsoft:accessibility_insights_for_web:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.