
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26161 is an untrusted pointer dereference vulnerability in the Windows Sensor Data Service that allows an authorized local attacker to elevate privileges. Disclosed on April 14, 2026, as part of Microsoft's monthly Patch Tuesday release, it affects a broad range of Windows versions including Windows 10 (1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), Windows Server 2019, Windows Server 2022, and Windows Server 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The vulnerability is rooted in improper input validation (CWE-20) and untrusted pointer dereference (CWE-822) within the Windows Sensor Data Service component. An attacker who already has low-privileged local access can supply malicious input that causes the service to dereference an untrusted pointer, enabling arbitrary code execution in a higher-privilege context. No user interaction is required, and the attack complexity is low, making it straightforward to exploit once local access is obtained. No public proof-of-concept or detailed technical write-up has been identified at this time (Microsoft MSRC).
Successful exploitation allows a low-privileged local attacker to escalate to SYSTEM-level privileges, resulting in complete compromise of confidentiality, integrity, and availability on the affected host. This affects a wide range of Windows desktop and server editions, meaning both end-user workstations and critical server infrastructure are at risk. Once SYSTEM privileges are obtained, an attacker could install malware, exfiltrate sensitive data, disable security controls, or use the compromised host as a pivot point for lateral movement within the network (Microsoft MSRC).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Microsoft MSRC). The EPSS score is approximately 0.088%, indicating a low near-term probability of exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Microsoft released patches on April 14, 2026, addressing this vulnerability across all affected products. Administrators should apply the following minimum build versions: Windows 10 1809 → 10.0.17763.8644; Windows 10 21H2 → 10.0.19044.7184; Windows 10 22H2 → 10.0.19045.7184; Windows 11 23H2 → 10.0.22631.6936; Windows 11 24H2 → 10.0.26100.8246; Windows 11 25H2 → 10.0.26200.8246; Windows 11 26H1 → 10.0.28000.1836; Windows Server 2019 → 10.0.17763.8644; Windows Server 2022 → 10.0.20348.5020; Windows Server 2022 23H2 → 10.0.25398.2274; Windows Server 2025 → 10.0.26100.32690. As a compensating control, restrict local interactive and remote desktop access to trusted, authorized users only to reduce the attack surface until patches can be applied (Microsoft MSRC).
The vulnerability was covered as part of broader April 2026 Patch Tuesday roundups by security vendors including Rapid7, Sophos, Lansweeper, and NSFOCUS, which noted it among the elevation-of-privilege issues addressed that month (Rapid7 Blog, Sophos Blog, Lansweeper Blog). No notable individual researcher commentary or significant social media discussion specific to this CVE has been identified beyond standard vulnerability database tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."