SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-33388

HIGH · CVSS 7.4 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An access control vulnerability in the Credentials Manager allows remote authenticated users with limited privileges to view, delete, or edit credential entries, potentially disrupting authentication for dependent devices. While actual credential values are not directly exposed, manipulation of entries could lead to indirect credential exposure. Organizations utilizing the affected Credentials Manager functionality should prioritize addressing this vulnerability to mitigate risks of unauthorized access and service disruption.

CVE
CVE-2026-33388
Severity
HIGH
CVSS
7.4
EPSS
0.28%

Original NVD Description

An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with limited privileges can view a limited subset of the available entries in the Credentials Manager. The actual credential values are not directly visible, but the user can delete entries or edit their properties. An attacker who deletes or edits an entry can disrupt authentication for dependent devices, and one who manipulates an entry's configuration may be able to indirectly obtain the credentials.