CVE-2026-27906

MEDIUM

Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.