CVE-2026-69826
massHeap Buffer Overflow in Windows Biometric Service Allows Network Privilege Escalation
CVE-2026-69826 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the Windows component that processes biometric authentication data used by features such as Windows Hello sign-in. According to the CVSS vector (AV:N/AC:L/PR:L/UI:R), an authorized attacker with low privileges who has network reachability to the target system can trigger the overflow through network-facing paths to the service, with some user interaction required. Successful exploitation allows the attacker to elevate privileges on the host, with high impact on confidentiality, integrity, and availability. Affected systems are Windows installations running the Biometric Service; the available data does not specify which Windows editions or version ranges are affected. Exploitation status: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only a 0.7% probability of exploitation within 30 days (51st percentile), so no active exploitation is currently known.
What to do: Install Microsoft's security update for CVE-2026-69826 via Windows Update as soon as it is released, prioritizing endpoints where biometric sign-in is enabled and users with remote or interactive session access. Because exploitation requires valid low-privilege credentials and network reachability, restrict remote access (e.g., RDP) to standard users and apply least-privilege account practices as interim risk reduction. Consult Microsoft's advisory for the definitive list of affected Windows versions, since the version ranges are not detailed in the available data.
| Microsoft Windows Biometric Service (Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.