CVE-2026-54123: Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability

Overview

Severity
Medium (CVSS 5.5)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Category
Information Disclosure
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Aug
Released
2026-08-11

Description

Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.

FAQ

What information could be disclosed by successfully exploiting this vulnerability? An attacker who successfully exploited this vulnerability could view Microsoft Defender for Endpoint configuration exclusion settings that are intended to be viewable only by administrators.

Affected Products (1)

System Center

  • Microsoft Defender for Endpoint for Mac

Acknowledgments

Abhishek Mundhra with PwC

Revision History

  • 2026-08-11: Information published.