PT-2026-108308 · Microsoft · Windows

·

CVE-2026-56857

·

Published

2026-10-08

·

Updated

2026-10-08

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description On Windows, the Root.Mkdir and Root.MkdirAll functions can create a directory at a junction target that is located outside the root, provided the junction points to an empty location. This issue occurs specifically when the last component of the path is a junction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-56857
GO-2026-6604

Affected Products

Windows