
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20826 is a local privilege escalation vulnerability caused by a race condition in the Tablet Windows User Interface (TWINUI) Subsystem. An authorized local attacker can exploit improper synchronization of shared resources to elevate privileges on affected Windows systems. It was disclosed and patched on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday. Affected products span Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2), and Windows Server 2016, 2019, 2022, 2022 23H2, and 2025. The CVSS v3.1 base score is 7.8 (High) per Microsoft's CNA assessment, and 7.0 (High) per NVD (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization — Race Condition), specifically within the TWINUI subsystem, which handles tablet-mode UI interactions in Windows. An attacker can exploit a time-of-check to time-of-use (TOCTOU) style race condition (CAPEC-29) by manipulating shared resources during concurrent execution to gain elevated privileges. Exploitation requires local access and low-level user privileges, but no user interaction is needed. No public proof-of-concept code has been identified at this time (Feedly, Microsoft MSRC).
Successful exploitation allows a low-privileged local attacker to escalate privileges to SYSTEM level, granting full administrative control over the affected Windows system. This could enable an attacker to install malware, modify system configurations, access sensitive data, disable security controls, or facilitate lateral movement within a network. The broad scope of affected platforms — including widely deployed Windows 10, Windows 11, and multiple Windows Server versions — significantly amplifies the potential organizational impact (Feedly).
Microsoft released patches for all affected products on January 13, 2026, as part of the January 2026 Patch Tuesday security updates. Organizations should apply the relevant cumulative updates to bring affected systems to the following minimum build versions: Windows 10 1607/Server 2016 → 10.0.14393.8783; Windows 10 1809/Server 2019 → 10.0.17763.8276; Windows 10 21H2 → 10.0.19044.6809; Windows 10 22H2 → 10.0.19045.6809; Windows 11 23H2 → 10.0.22631.6491; Windows 11 24H2/Server 2025 → 10.0.26100.7623; Windows 11 25H2 → 10.0.26200.7623; Windows Server 2022 → 10.0.20348.4648; Windows Server 2022 23H2 → 10.0.25398.2092. Prioritize patching systems where low-privileged users have local interactive access, and monitor for unusual privilege escalation activity as a compensating control (Microsoft MSRC, Feedly).
CVE-2026-20826 was covered as part of broader January 2026 Patch Tuesday roundups by multiple security outlets. Trend Micro's Zero Day Initiative published a security update review for January 2026, and Sophos noted Microsoft addressed 113+ CVEs in the January release (ZDI Blog, Sophos Blog). BleepingComputer reported on the January 2026 Patch Tuesday fixing 114 flaws including 3 zero-days, with this vulnerability noted among the privilege escalation issues addressed (BleepingComputer). No significant independent researcher commentary or social media controversy specific to this CVE was identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."