Description
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Published: 2026-07-14
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Windows Admin Center allows an attacker who is already granted network access to bypass authentication controls and gain elevated privileges on the target system. The vulnerability is a flaw in authentication handling that enables privilege escalation, potentially allowing the attacker to perform any action that higher‑level users can, thereby compromising confidentiality, integrity, and availability of the managed infrastructure.

Affected Systems

The affected product is Microsoft Windows Admin Center. Version information is not specified in the available data, so any installation of this product is potentially vulnerable unless proven otherwise.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity. The EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is over the network, requiring the attacker to connect to the Admin Center from a client that has network access. No known public exploit is documented, but given the high CVSS score and the network path, entities should treat this as a serious risk.

Generated by OpenCVE AI on July 31, 2026 at 09:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft patch for Windows Admin Center as soon as it becomes available
  • Limit network access to the Windows Admin Center only from trusted management hosts and enforce strict firewall rules
  • Enable and monitor audit logs for anomalous authentication attempts and privilege escalations

Generated by OpenCVE AI on July 31, 2026 at 09:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Title Windows Admin Center Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows Admin Center
Weaknesses CWE-287
CPEs cpe:2.3:a:microsoft:windows_admin_center:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows Admin Center
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows Admin Center
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:53:32.832Z

Reserved: 2026-06-19T13:53:31.989Z

Link: CVE-2026-56169

cve-icon Vulnrichment

Updated: 2026-07-15T10:28:36.351Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:30:05Z

Weaknesses