Description
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Published: 2026-07-26
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Edge (Chromium-based) is vulnerable to an information disclosure flaw that allows an unauthorized attacker to read files or directories that should be protected. The flaw arises from insufficient access control on Edge’s local file handling, allowing exposed resources to be accessed over a network. The weakness is classified as CWE‑552 (Access Control).

Affected Systems

The vulnerability affects Microsoft Edge (Chromium-based) on all installations prior to the security update described by Microsoft. No specific version range is listed, so all versions before the update may be impacted.

Risk and Exploitability

The CVSS score of 7.4 indicates a high severity. The EPSS score is less than 1%, suggesting a low current exploitation probability. The vulnerability is not in the CISA KEV catalog. An attacker can exploit it from a remote network location to disclose files or directories that should otherwise be restricted. The attack appears to involve remote network access, but no privilege escalation or personal user interaction is described.

Generated by OpenCVE AI on August 3, 2026 at 18:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge update that includes the CVE‑2026‑57990 fix.
  • If patching cannot occur immediately, restrict Edge’s local file service endpoints by blocking inbound network connections through firewall rules or network segmentation.
  • Disable any Edge features that expose local directories, such as shared browsing or file sharing, or remove temporary files that Edge can serve over the network.
  • Monitor network traffic for repeated attempts to access Edge’s local file service endpoints.

Generated by OpenCVE AI on August 3, 2026 at 18:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 26 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Title Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-552
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-14T17:21:04.736Z

Reserved: 2026-06-26T17:45:44.854Z

Link: CVE-2026-57990

cve-icon Vulnrichment

Updated: 2026-07-27T14:04:42.598Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-26T18:18:25.153

Modified: 2026-08-03T14:54:26.487

Link: CVE-2026-57990

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:15:04Z

Weaknesses
  • CWE-552

    Files or Directories Accessible to External Parties