Description
Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Published: 2026-08-28
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

The flaw arises from an incorrect authorization check in Microsoft Edge (Chromium-based). The vulnerability permits an unauthorized attacker to disclose information over a network. The weakness is classified as CWE‑863, indicating an authorization bypass. Because the description does not specify the exact type or scope of data that can be disclosed, the potential impact may range widely, but it remains an information disclosure flaw.

Affected Systems

The vulnerable component is Microsoft Edge (Chromium-based). No specific version information is provided, so all supported Windows installations of Edge that have not yet received the Microsoft patch may be affected. All users running Edge are therefore at risk until the update is applied.

Risk and Exploitability

The CVSS score of 5.4 indicates a medium severity. The EPSS score is not available, so the likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. The vulnerability description states that exploitation occurs over a network, but it does not detail additional prerequisites, meaning that an attacker would need a way to invoke the affected functionality from outside the local machine to trigger the disclosure.

Generated by OpenCVE AI on August 28, 2026 at 21:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest version available through Windows Update or the Microsoft Edge release site to apply the fix for CVE-2026-62904.
  • After installing the update, restart Edge or the system to ensure all components reload with the updated authorization checks.
  • Continuously monitor Edge network traffic and browser logs for anomalous activity that could indicate an attempt to exploit the disclosure vulnerability, and consider blocking suspicious network requests until the patch is fully deployed.

Generated by OpenCVE AI on August 28, 2026 at 21:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft edge
CPEs cpe:2.3:a:microsoft:edge:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:edge:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:edge:*:*:*:*:*:linux:*:*
cpe:2.3:a:microsoft:edge:*:*:*:*:*:mac:*:*
cpe:2.3:a:microsoft:edge:*:*:*:*:*:windows:*:*
Vendors & Products Microsoft edge

Mon, 31 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Title Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-863
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-16T16:25:12.722Z

Reserved: 2026-07-14T21:25:21.035Z

Link: CVE-2026-62904

cve-icon Vulnrichment

Updated: 2026-08-31T15:21:20.903Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-28T20:19:25.130

Modified: 2026-09-11T17:17:33.433

Link: CVE-2026-62904

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:15:04Z

Weaknesses