
CVE-2026-20982 Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege. https://www.cve.org/CVERecord?id=CVE-2026-20982
Post summary
The CVE-2026-20982 describes a path traversal flaw in ShortcutService that can enable a privileged local attacker to create a file with system privilege. No PoC, exploit code, or patch information is provided.

