Sceawere

Vulnerability Detail

CVE-2026-62904UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Edge Incorrect Authorization Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
3h ago
Vendor
Microsoft
Product
Microsoft Edge (Chromium-based)
Attack Type
CWE-863: Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-08-28T20:19:25.130Z",
  "pubdate": "2026-08-28T20:19:25.130Z",
  "executiveSummary": "This vulnerability involves an incorrect authorization flaw within the Chromium-based architecture of Microsoft Edge.\nThe security defect permits an unauthorized remote attacker to perform unauthorized data disclosure across a network, effectively bypassing intended access control restrictions.\nThe vulnerability resides in how the browser handles authorization tokens or access permissions when interacting with network resources, potentially leading to the leakage of sensitive information.\nThe primary impact is the loss of data confidentiality, as attackers can intercept or solicit information that should be protected by standard authorization policies.\nExploitation does not require prior authentication from the attacker, making it a significant concern for environments where Edge is deployed across diverse network segments.\nThe risk implication is elevated due to the potential for unauthorized access to sensitive local or network-based data without user interaction or authentication headers.\nSuccessful exploitation allows an unauthenticated remote actor to leverage the browser's misconfiguration to disclose sensitive information that would otherwise be restricted under normal authorization schemas.",
  "technicalDetails": "The vulnerability is rooted in an incorrect authorization implementation within the Microsoft Edge (Chromium-based) browser environment. At its core, the issue arises from a failure of the browser to properly validate authorization requirements during resource requests, leading to an insecure state where sensitive data is exposed to unauthorized entities.\nThe root cause appears to be an improper check in the browser's authorization logic, which governs access to specific network resources or internal processes. Under normal operational conditions, the browser is expected to enforce strict authorization controls, verifying that a requester possesses the necessary permissions before allowing access to a resource. However, in this vulnerable configuration, the authorization mechanism fails to validate these prerequisites correctly, enabling an unauthorized actor to gain access to data that should be protected.\nFrom an exploitation perspective, an attacker can manipulate the request flow by initiating a specially crafted interaction that triggers the browser to disclose information over the network. Because the underlying logic fails to verify the authorization status of the origin or the requester, the browser treats the request as legitimate, thereby returning the requested data to the attacker.\nThe attack flow proceeds as follows: First, the attacker identifies a network-accessible endpoint or resource that is mediated by the browser's vulnerable authorization component. Second, the attacker sends a crafted network request—often via a malicious script or intercepted traffic—aimed at the identified resource. Third, the browser's engine, failing to perform the requisite authorization checks, processes the request and retrieves the information. Finally, the browser returns the sensitive data to the attacker, completing the unauthorized disclosure.\nThe impact of this exploit is significant, as it effectively bypasses the Principle of Least Privilege by allowing unauthenticated remote access to information that was intended to be restricted. Since the vulnerability is located within the browser's core processing logic, the scope of the potential data disclosure depends on the resources available to the browser instance at the time of the exploit, including potentially sensitive cookies, session tokens, or internal network metadata. Because no prior authentication is required, an attacker can conduct these operations remotely over the network, making this a critical concern for secure network infrastructure."
}
CVE-2026-62904: Microsoft Edge Incorrect Authorization Disclosure (MEDIUM Severity, CVSS: 5.4) - Sceawere