CVE-2026-20484: Medium severity vulnerability
In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS11053160
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20484?
CVE-2026-20484 has a risk score of 15, indicating a critical severity level.
How do I fix CVE-2026-20484?
To fix CVE-2026-20484, apply the patch identified as ALPS11053160.
What type of vulnerability is CVE-2026-20484?
CVE-2026-20484 is an information disclosure vulnerability due to a missing permission check.
Who is affected by CVE-2026-20484?
CVE-2026-20484 can potentially affect any system utilizing TFA that has the System privilege without necessary permission checks.
Does CVE-2026-20484 require user interaction for exploitation?
No, CVE-2026-20484 does not require user interaction for exploitation.