Description
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.
Published: 2026-07-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper access control in Microsoft Configuration Manager permits an attacker who already has some level of authorized access to elevate their privileges over a network. The flaw is an authorization bypass (CWE‑284), allowing the attacker to gain higher privileges and potentially compromise system integrity and confidentiality within the network.

Affected Systems

Microsoft Configuration Manager releases 2503, 2509, and 2603 are affected.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is within an internal network; it requires the attacker to have some level of authorized access to a Configuration Manager instance and network connectivity.

Generated by OpenCVE AI on July 31, 2026 at 05:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Configuration Manager update available from Microsoft to enforce least privilege for configuration tasks.
  • Monitor administrative logs for unexpected privilege changes and audit configuration modifications.
  • Apply network segmentation to isolate the Configuration Manager servers from general user traffic and reduce the attack surface.

Generated by OpenCVE AI on July 31, 2026 at 05:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Description Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.
Title Configuration Manager Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft configuration Manager 2503
Microsoft configuration Manager 2509
Microsoft configuration Manager 2603
Weaknesses CWE-284
CPEs cpe:2.3:a:microsoft:configuration_manager_2503:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:configuration_manager_2509:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:configuration_manager_2603:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft configuration Manager 2503
Microsoft configuration Manager 2509
Microsoft configuration Manager 2603
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Configuration Manager 2503 Configuration Manager 2509 Configuration Manager 2603
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:53:51.760Z

Reserved: 2026-05-18T23:53:33.897Z

Link: CVE-2026-47301

cve-icon Vulnrichment

Updated: 2026-07-14T19:12:32.886Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:45:03Z

Weaknesses