Information Disclosure in Microsoft Defender for Endpoint
CVE-2026-54123

5.5MEDIUM

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
11 August 2026

What is CVE-2026-54123?

A vulnerability has been identified in Microsoft Defender for Endpoint that permits an authorized attacker to access and disclose sensitive information locally. This exposure could lead to unauthorized access to confidential data, posing a significant risk to data integrity and security. Users are advised to apply the latest security updates to mitigate risks associated with this vulnerability.

Affected Version(s)

Microsoft Defender for Endpoint for Mac 101.0.0 < 101.26042.0020

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.