
PEACH
Un cadre d’isolation des locataires
CVE-2026-57980 is an authentication bypass vulnerability in Microsoft Edge (Chromium-based) that allows an unauthorized network attacker to perform tampering by exploiting an alternate path or channel. It affects Microsoft Edge (Chromium-based) versions from 1.0.0.0 up to (but not including) 150.0.4078.80. The vulnerability was published on July 16, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 5.4 (Medium) (Microsoft MSRC).
The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), meaning the browser fails to enforce authentication controls uniformly across all code paths or communication channels. An unauthenticated remote attacker can exploit this over a network with low attack complexity, though user interaction is required. The vulnerability allows tampering with application state or data by circumventing security controls through an unprotected alternate path. No public technical write-ups or proof-of-concept code have been identified at this time (Microsoft MSRC).
Successful exploitation results in limited confidentiality and integrity impacts — an attacker can read and tamper with some data or application settings without authorization, but there is no availability impact. The scope is unchanged, meaning the impact is confined to the vulnerable Edge browser instance rather than extending to the underlying system. While the individual impact per metric is low, the ability to bypass authentication and modify data without credentials represents a meaningful security control failure for affected users (Microsoft MSRC).
Microsoft has released a patch addressing this vulnerability in Microsoft Edge (Chromium-based) version 150.0.4078.80 and later, published on July 16, 2026. Users and administrators should update Microsoft Edge to version 150.0.4078.80 or higher immediately via the browser's built-in update mechanism or enterprise deployment tools. No configuration-based workarounds have been published; upgrading to the patched version is the recommended remediation (Microsoft MSRC).
Coverage of CVE-2026-57980 has been limited to automated vulnerability tracking platforms such as VulDB, CVEfeed.io, and cve.report shortly after disclosure. No notable independent researcher commentary, vendor statements beyond the MSRC advisory, or significant media coverage has been identified at this time (Microsoft MSRC).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."