What is CVE-2026-20484?
CVE-2026-20484 is an information disclosure vulnerability in TFA due to a missing permission check. If a malicious actor has already obtained System privilege, they can exploit this locally without user interaction to access sensitive information. Apply Patch ID ALPS11053160 to mitigate the issue.
Azərbaycanca: CVE-2026-20484 TFA-da icazə yoxlamasının olmaması səbəbindən mümkün informasiya sızıntısıdır. Bu zəiflik Sistem imtiyazları əldə etmiş yerli təcavüzkara istifadəçi müdaxiləsi olmadan məxfi məlumatları əldə etməyə imkan verir. Təsirə məruz qalan sistemlərdə ALPS11053160 yaması tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Who can exploit CVE-2026-20484?
A local attacker who has already obtained System privilege can exploit it.
What patch should be applied to fix CVE-2026-20484?
Patch ID ALPS11053160 should be applied.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.