Home
MEDIUM: 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C 10.0.19044.0 (custom) before 10.0.19044.7184
affected
10.0.19045.0 (custom) before 10.0.19045.7184
affected
10.0.22631.0 (custom) before 10.0.22631.6936
affected
10.0.22631.0 (custom) before 10.0.22631.6936
affected
10.0.26100.0 (custom) before 10.0.26100.8246
affected
10.0.26200.0 (custom) before 10.0.26200.8246
affected
10.0.28000.0 (custom) before 10.0.28000.1836
affected
Description
Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.
Problem types
CWE-20: Improper Input Validation
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27906 (Windows Hello Security Feature Bypass Vulnerability)