CVE-2026-57980
Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-57980 is an authentication bypass vulnerability in Microsoft Edge (Chromium-based) that allows an unauthorized network attacker to perform tampering by exploiting an alternate path or channel. It affects Microsoft Edge (Chromium-based) versions from 1.0.0.0 up to (but not including) 150.0.4078.80. The vulnerability was published on July 16, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 5.4 (Medium) (Microsoft MSRC).

Détails techniques

The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), meaning the browser fails to enforce authentication controls uniformly across all code paths or communication channels. An unauthenticated remote attacker can exploit this over a network with low attack complexity, though user interaction is required. The vulnerability allows tampering with application state or data by circumventing security controls through an unprotected alternate path. No public technical write-ups or proof-of-concept code have been identified at this time (Microsoft MSRC).

Impact

Successful exploitation results in limited confidentiality and integrity impacts — an attacker can read and tamper with some data or application settings without authorization, but there is no availability impact. The scope is unchanged, meaning the impact is confined to the vulnerable Edge browser instance rather than extending to the underlying system. While the individual impact per metric is low, the ability to bypass authentication and modify data without credentials represents a meaningful security control failure for affected users (Microsoft MSRC).

Atténuation et solutions de contournement

Microsoft has released a patch addressing this vulnerability in Microsoft Edge (Chromium-based) version 150.0.4078.80 and later, published on July 16, 2026. Users and administrators should update Microsoft Edge to version 150.0.4078.80 or higher immediately via the browser's built-in update mechanism or enterprise deployment tools. No configuration-based workarounds have been published; upgrading to the patched version is the recommended remediation (Microsoft MSRC).

Réactions de la communauté

Coverage of CVE-2026-57980 has been limited to automated vulnerability tracking platforms such as VulDB, CVEfeed.io, and cve.report shortly after disclosure. No notable independent researcher commentary, vendor statements beyond the MSRC advisory, or significant media coverage has been identified at this time (Microsoft MSRC).

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités