CVE-2026-32079 is an information disclosure vulnerability in Windows File Explorer that allows an authorized local user to expose sensitive information to unauthorized actors through improper access controls. The flaw affects Windows File Explorer functionality and requires valid credentials to exploit. The vulnerability carries a CVSS score of 5.5 (Medium severity) with a local attack vector, low complexity, and requirement for low privileges. The primary impact is confidentiality compromise, allowing attackers to read sensitive data, while integrity and availability remain unaffected. The attack requires no user interaction to succeed once an authorized account is compromised. There is no current evidence of active exploitation in the wild, as indicated by its absence from the Known Exploited Vulnerabilities catalog and inactive status on vulnerability tracking lists. The EPSS score of 0.00044 suggests minimal exploitation probability compared to the broader CVE landscape, and community attention remains limited. Organizations should prioritize patching based on their Windows File Explorer usage patterns and the presence of untrusted local users on affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.14393.9060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:* | ||
< 10.0.14393.9060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.