Description
Improper link resolution before file access ('link following') in Windows Container Manager Service allows an authorized attacker to bypass a security feature locally.
Published: 2026-09-08
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation / Security Feature Bypass
Action: Assess Impact
AI Analysis

Impact

The vulnerability arises from improper link resolution before file access in the Windows Container Manager Service. This flaw, identified as CWE‑59, enables an attacker who already has local system‑access privileges to bypass a security feature that protects container configuration files, potentially giving unauthorized access to resources normally restricted by that feature.

Affected Systems

The flaw affects Microsoft Windows 11 releases 23H2, 24H2, 25H2, and 26H1 on both x64 and arm64 architectures, as listed in the Vendor's advisory.

Risk and Exploitability

The calculated CVSS score of 4.7 indicates moderate risk, and no EPSS data is currently available. The vulnerability is not listed in CISA's KEV catalog. Because exploitation requires local authorization, the attack vector is limited to the infected host; however, once the local attacker gains sufficient privileges, the feature bypass could assist in escalating or persisting. The lack of a publicly known exploit or broad distribution reduces immediate threat.

Generated by OpenCVE AI on September 10, 2026 at 00:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Windows security updates that include the fix for the Windows Container Manager Service, as referenced in Microsoft's update guide for CVE‑2026‑69771.
  • Minimize local user privileges on systems that run containers, ensuring that only trusted accounts have the ability to modify container configuration files.
  • Enforce least‑privilege container execution policies and network segmentation to limit the impact of a potential feature bypass.

Generated by OpenCVE AI on September 10, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Vendors & Products Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper link resolution before file access ('link following') in Windows Container Manager Service allows an authorized attacker to bypass a security feature locally.
Title Windows Container Manager Service Security Feature Bypass Vulnerability
First Time appeared Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Weaknesses CWE-59
CPEs cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 23h2 Windows 11 23h2 Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:32:08.139Z

Reserved: 2026-08-03T22:46:09.552Z

Link: CVE-2026-69771

cve-icon Vulnrichment

Updated: 2026-09-08T18:24:38.917Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:48.497

Modified: 2026-09-22T19:54:20.060

Link: CVE-2026-69771

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T21:08:55Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')