CVE-2026-28659: Critical severity MicroXR MicroXR Blobstore vulnerability
Published Sep 8, 2026
·Updated
In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
1 affected component
MicroXR MicroXR Blobstore
Event History
Sep 8, 2026
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
Description
Data Sourced
via NVD·08:17 PM
DescriptionSeverity