
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20838 is a Windows Kernel information disclosure vulnerability caused by the generation of error messages containing sensitive information. It affects Windows 11 (versions 23H2, 24H2, and 25H2) and Windows Server 2022 (including the 23H2 edition) and Windows Server 2025. The vulnerability was disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday. It carries a CVSS v3.1 base score of 5.5 (Medium), assigned by Microsoft (Microsoft MSRC, Feedly).
The root cause is classified as CWE-209 (Generation of Error Message Containing Sensitive Information), where the Windows Kernel improperly includes sensitive data within error messages that can be read by a low-privileged local user. The attack vector is local, requiring an authorized (low-privilege) attacker with no user interaction needed. No public proof-of-concept or detailed technical write-up describing the specific kernel code path or triggering mechanism has been published as of the time of this report (Microsoft MSRC, Feedly).
Successful exploitation results in the disclosure of sensitive information from the Windows Kernel to a locally authenticated, low-privilege attacker. The impact is limited to confidentiality — there is no integrity or availability impact. While the vulnerability itself does not enable code execution or privilege escalation directly, the exposed kernel-level information could potentially be leveraged as a stepping stone for more sophisticated attacks or to facilitate privilege escalation through other means (Microsoft MSRC, Feedly).
Microsoft released patches on January 13, 2026, as part of the January 2026 Patch Tuesday. Affected systems should be updated to the following minimum versions: Windows 11 23H2 → 10.0.22631.6491, Windows 11 24H2 → 10.0.26100.7623, Windows 11 25H2 → 10.0.26200.7623, Windows Server 2022 → 10.0.20348.4648, Windows Server 2022 23H2 Edition → 10.0.25398.2092, Windows Server 2025 → 10.0.26100.32230. No configuration-based workarounds have been published; applying the security update is the recommended remediation. Organizations should prioritize patching systems accessible to lower-privileged users (Microsoft MSRC, Feedly).
CVE-2026-20838 was covered as part of broader January 2026 Patch Tuesday roundups by several security outlets including BleepingComputer, Sophos, Zero Day Initiative, and CyberSecurityNews, though it received no specific individual attention given its medium severity and lack of active exploitation. The Zero Day Initiative's January 2026 security update review and Sophos's Patch Tuesday blog both noted the overall release of 114 CVEs but did not single out this vulnerability for special commentary (Zero Day Initiative, Sophos Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."