
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20834 is an absolute path traversal vulnerability in Windows Shell that allows an unauthorized attacker to perform spoofing via a physical attack. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects a broad range of Windows versions spanning Windows Server 2008 through Windows Server 2025, and Windows 10/11 across multiple release versions. The vulnerability carries a CVSS v3.1 base score of 4.6 (Medium), reflecting its physical attack vector requirement (Microsoft MSRC, Feedly).
The vulnerability is classified under CWE-36 (Absolute Path Traversal) and CWE-359 (Exposure of Private Personal Information to an Unauthorized Actor). An attacker with physical access to a vulnerable Windows system can exploit improper path handling in Windows Shell to traverse absolute file paths and access sensitive files without requiring any privileges or user interaction. The attack complexity is low, but exploitation is constrained to physical presence at the target machine, limiting its remote exploitability (Microsoft MSRC, Feedly).
Successful exploitation results in high confidentiality impact, enabling an attacker to read sensitive or private files on the affected system, potentially exposing personal information and other confidential data. There is no integrity or availability impact. The spoofing capability associated with this vulnerability may allow an attacker to misrepresent file or system identity during physical access scenarios. The wide range of affected products — from Windows Server 2008 to Windows Server 2025 and Windows 10/11 — means the potential attack surface is extensive across enterprise and legacy environments (Feedly).
Microsoft released security patches on January 13, 2026, addressing this vulnerability across all affected platforms. Patched versions include: Windows 10 1607 (10.0.14393.8783), Windows 10 1809/Windows Server 2019 (10.0.17763.8276), Windows 10 21H2 (10.0.19044.6809), Windows 10 22H2 (10.0.19045.6809), Windows 11 23H2 (10.0.22631.6491), Windows 11 24H2 (10.0.26100.7623), Windows 11 25H2 (10.0.26200.7623), Windows Server 2016 (10.0.14393.8783), Windows Server 2022 (10.0.20348.4648), Windows Server 2022 23H2 (10.0.25398.2092), and Windows Server 2025 (10.0.26100.32230). In addition to patching, organizations should enforce physical security controls to restrict unauthorized physical access to Windows systems (Microsoft MSRC).
CVE-2026-20834 was covered as part of broader reporting on Microsoft's January 2026 Patch Tuesday, which addressed 114 vulnerabilities including 3 zero-days. Security outlets such as BleepingComputer, CyberSecurityNews, and GBHackers reported on the patch release, though CVE-2026-20834 received limited individual attention given its medium severity and physical-access-only exploitation requirement (BleepingComputer, CyberSecurityNews).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."