CVE-2026-66326
published 2026-08-04CVE-2026-66326: Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
PriorityP356high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.40%
33.6th percentile
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge_chromium | < 151.0.4129.59 | 151.0.4129.59 |
| microsoft | microsoft_edge | >= 1.0.0.0 < 151.0.4129.59 | 151.0.4129.59 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
ghsa_unreviewed·2026-08-04
CVE-2026-66326 [MEDIUM] CWE-862 Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
VulDB
Microsoft Edge up to 150.0.4078.99 improper authorization
vuldb·2026-08-04·CVSS 6.5
CVE-2026-66326 [MEDIUM] Microsoft Edge up to 150.0.4078.99 improper authorization
A vulnerability marked as critical has been reported in Microsoft Edge. Affected is an unknown function. Performing a manipulation results in improper authorization.
This vulnerability is known as CVE-2026-66326. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-04
Published