CVE-2026-20839
vulnerability analysis and mitigation

Overview

CVE-2026-20839 is an improper access control vulnerability in the Windows Client-Side Caching (CSC) Service that allows a low-privileged local attacker to disclose sensitive cached information. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects a wide range of Windows versions including Windows 10 (1607 through 22H2), Windows 11 (23H2 through 25H2), Windows Server 2008 R2 SP1 through Windows Server 2025. It carries a CVSS v3.1 base score of 5.5 (Medium) (Microsoft MSRC, Feedly).

Technical details

The vulnerability is rooted in insufficient access controls on the Windows Client-Side Caching (CSC) Service, which is responsible for caching network file share data locally on Windows systems to support offline file access (CWE-284: Improper Access Control). An authorized but low-privileged local user can exploit these inadequate access restrictions to read cached data that should be protected from their access level. The attack vector is local, requires low privileges, no user interaction, and has low attack complexity, making it straightforward for any authenticated local user to attempt (Microsoft MSRC, Feedly). No public proof-of-concept code has been identified at this time.

Impact

Successful exploitation results in high-impact information disclosure with no effect on system integrity or availability. A low-privileged local attacker could read sensitive data cached by the CSC Service, potentially including credentials, file contents, and other confidential information sourced from network shares. While the attack is confined to the local system (unchanged scope), the exposed cached data could facilitate lateral movement or privilege escalation if credentials or sensitive configuration data are among the disclosed information (Feedly).

Mitigation and workarounds

Microsoft released patches on January 13, 2026 as part of the January 2026 Patch Tuesday. Affected systems should be updated to the following minimum build versions: Windows 10 21H2 (10.0.19044.6809), Windows 10 22H2 (10.0.19045.6809), Windows 11 23H2 (10.0.22631.6491), Windows 11 24H2 (10.0.26100.7623), Windows 11 25H2 (10.0.26200.7623), Windows Server 2016 (10.0.14393.8783), Windows Server 2019 (10.0.17763.8276), Windows Server 2022 (10.0.20348.4648), Windows Server 2022 23H2 (10.0.25398.2092), and Windows Server 2025 (10.0.26100.32230) (Microsoft MSRC). As a complementary measure, organizations should enforce the principle of least privilege for local user accounts and restrict local access to sensitive systems where feasible.

Community reactions

CVE-2026-20839 was covered as part of broader January 2026 Patch Tuesday roundups by security outlets including BleepingComputer, Sophos, Zero Day Initiative, and CyberSecurityNews, though it did not receive individual focused attention given its medium severity rating (BleepingComputer, Sophos, ZDI). Community sentiment reflects routine patch prioritization, with no significant alarm raised given the local-only attack vector and absence of active exploitation.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management