Description
Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a relative path traversal flaw in Microsoft Edge (Chromium-based) that permits an attacker to invoke arbitrary code execution. The weakness allows unauthorized code to be run, compromising confidentiality, integrity, and availability of the compromised system. The flaw is rooted in inadequate validation of file paths and is identified by CWE-23.

Affected Systems

Microsoft Edge (Chromium-based) – the CVE does not specify affected versions; it is unknown which releases are impacted. All current releases might be affected, but this is not confirmed.

Risk and Exploitability

The 7.1 indicates a high severity. The EPSS score is <1%, indicating a very low exploitation probability, and the vulnerability is not currently listed in the CISA KEV. Based on the description, the likely attack vector is a remote network attack where an unauthorized attacker crafts requests that exploit the path traversal to execute code on the target system. Because the flaw does not require authentication, even low‑privileged or domain users could trigger it once network access is available.

Generated by OpenCVE AI on July 21, 2026 at 09:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest version that includes the path traversal fix.
  • Restrict external network access to Microsoft Edge by configuring firewall rules to block incoming traffic that could exploit the path traversal vulnerability or limiting Edge's exposure to trusted networks only.
  • Enable Windows Defender SmartScreen or another endpoint protection system to detect and block attempts to inject malicious file paths, and monitor Edge logs for suspicious activity.

Generated by OpenCVE AI on July 21, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-23
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-23T23:56:09.518Z

Reserved: 2026-06-26T17:45:44.854Z

Link: CVE-2026-57988

cve-icon Vulnrichment

Updated: 2026-07-06T11:40:44.297Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:30:04Z

Weaknesses
  • CWE-23

    Relative Path Traversal