CVE-2026-57978
published 2026-07-26CVE-2026-57978: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
PriorityP424medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_edge | >= 1.0.0.0 < 150.0.4078.99 | 150.0.4078.99 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Edge up to 150.0.4078.80 improper authorization (EUVD-2026-49057)
vuldb·2026-07-26·CVSS 5.4
CVE-2026-57978 [MEDIUM] Microsoft Edge up to 150.0.4078.80 improper authorization (EUVD-2026-49057)
A vulnerability has been found in Microsoft Edge and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper authorization.
This vulnerability is documented as CVE-2026-57978. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
GHSA
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
ghsa_unreviewed·2026-07-26
CVE-2026-57978 [MEDIUM] CWE-346 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-26
Published