MEDIUM
CVE-2026-20805
CVSS
5.5
KEV
Description
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
Summary dbcve.org
CVE-2026-20805 is a local information disclosure vulnerability in Windows Desktop Windows Manager (DWM) that allows an authorized local attacker to access sensitive information that should be protected from unprivileged users.
Mitigation
Apply the relevant Microsoft Windows security update for Desktop Windows Manager through Windows Update or enterprise patch management systems.
Weakness (CWE)
CWE-200
Information Exposure
EPSS Score
5.19%
Probability of exploitation in next 30 days
92.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.