Overview
What is CVE-2026-72980?
Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.
Vulnerability intelligence
CVE-2026-72980 and is rated Medium severity with a CVSS score of 4.4. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.