CVE-2026-20472: Medium severity vulnerability
In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10991467; Issue ID: MSV-7764.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TFAto a version that resolves this vulnerability.Patch ALPS10991467 - Compensating control
Mitigate local DoS risk by limiting System-privileged access for untrusted users/processes, since exploitation can occur after a malicious actor has obtained the System privilege and requires no user interaction.