CVE-2026-57990

Microsoft · Edge (Chromium-based)

An information disclosure vulnerability in Microsoft Edge (Chromium-based) allows unauthorized remote attackers to access sensitive system files or directories via crafted HTTP requests.

Executive summary

An information disclosure vulnerability in Microsoft Edge (Chromium-based) could allow remote attackers to gain unauthorized access to sensitive system resources.

Vulnerability

This vulnerability involves improperly configured access controls that permit unauthorized, unauthenticated attackers to disclose information over a network. The flaw allows external parties to probe for accessible directories or files by bypassing standard authentication mechanisms.

Business impact

Successful exploitation allows an attacker to retrieve sensitive system information, which may lead to further system compromise or unauthorized data exposure. Given the CVSS score of 7.4, this vulnerability represents a high risk to organizational data confidentiality, especially if the browser is used to access internal corporate environments.

Remediation

Immediate Action: Update Microsoft Edge to version 150.0.4078.99 or later immediately to apply the vendor-supplied security patches.

Proactive Monitoring: Review web server and network access logs for anomalous HTTP requests targeting system directories or unexpected recursive file access patterns.

Compensating Controls: Ensure that Web Application Firewalls (WAF) are configured to block requests containing directory traversal sequences or suspicious path probing patterns.

Exploitation status

Public Exploit Available: False

Analyst recommendation

This vulnerability presents a significant risk to data privacy and system integrity. IT administrators must prioritize the deployment of the 150.0.4078.99 update across all endpoints to remediate the underlying configuration flaw and prevent potential information disclosure.