Impact
The vulnerability is a relative path traversal flaw in Windows Admin Center that permits an attacker who already has authorized access to supply crafted path inputs and run arbitrary code on the hosting Windows system. This weakness, classified as CWE‑23, enables execution of code over the network without the need for the attacker to exploit a separate authentication mechanism. The documented impact is therefore loss of confidentiality, integrity, and availability of the affected host whenever the attacker succeeds in uploading or executing a file at an arbitrary location.
Affected Systems
Microsoft Windows Admin Center instances that have not installed the security update for CVE‑2026‑56196 are impacted. Because the vendor did not publish a version range, consider every deployment that predates the patch as vulnerable.
Risk and Exploitability
The CVSS score of 8.8 places the issue in the high severity range, but the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. An attacker needs authorized network access to the WAC service; once such access is available, the relative path traversal can be used to achieve remote code execution on the Windows host.
OpenCVE Enrichment