Description
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
Published: 2026-07-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authentication flaw in Windows Admin Center permits an attacker who already has authorized access to read sensitive configuration or system information over the network, effectively compromising confidentiality. The flaw arises from improper validation of user credentials or session tokens, enabling the disclosure of data that should be protected. This vulnerability is classified as CWE-287 (Authentication Bypass) and CWE-94 (Improper Control of Generation of Code).

Affected Systems

Microsoft Windows Admin Center is the affected product. The vulnerability applies to all installations where the authentication mechanism has not been updated to the latest patch. No specific version range is documented in the advisory, so all current releases should be considered vulnerable until a patch is applied.

Risk and Exploitability

With a CVSS score of 6.5, the vulnerability presents moderate risk; however, its EPSS score of less than 1% suggests that exploitation attempts are unlikely at present. The vulnerability is not listed in CISA's KEV catalog, indicating that no widespread exploits are known. The attack vector is network-based and requires the attacker to already have authorized access to the Windows Admin Center instance.

Generated by OpenCVE AI on July 31, 2026 at 09:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Windows Admin Center security update from Microsoft.
  • Restrict network access to the Windows Admin Center instance to trusted users and IP ranges.
  • Disable or remove unused or overly privileged accounts that can access the Admin Center.

Generated by OpenCVE AI on July 31, 2026 at 09:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
Title Windows Admin Center Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft windows Admin Center
Weaknesses CWE-287
CWE-94
CPEs cpe:2.3:a:microsoft:windows_admin_center:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows Admin Center
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows Admin Center
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:53:35.547Z

Reserved: 2026-06-19T13:54:04.006Z

Link: CVE-2026-56185

cve-icon Vulnrichment

Updated: 2026-07-15T15:52:32.683Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:15:06Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')