Description
Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
Published: 2026-07-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a relative path traversal flaw in Windows Admin Center that permits an attacker who already has authorized access to supply crafted path inputs and run arbitrary code on the hosting Windows system. This weakness, classified as CWE‑23, enables execution of code over the network without the need for the attacker to exploit a separate authentication mechanism. The documented impact is therefore loss of confidentiality, integrity, and availability of the affected host whenever the attacker succeeds in uploading or executing a file at an arbitrary location.

Affected Systems

Microsoft Windows Admin Center instances that have not installed the security update for CVE‑2026‑56196 are impacted. Because the vendor did not publish a version range, consider every deployment that predates the patch as vulnerable.

Risk and Exploitability

The CVSS score of 8.8 places the issue in the high severity range, but the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. An attacker needs authorized network access to the WAC service; once such access is available, the relative path traversal can be used to achieve remote code execution on the Windows host.

Generated by OpenCVE AI on August 1, 2026 at 09:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the Microsoft security update that addresses CVE‑2026‑56196 to bring Windows Admin Center up to the latest secure version.
  • Apply least‑privilege principles to users who manage WAC, removing or disabling unused administrative accounts.
  • Limit the exposure of WAC to trusted networks by configuring firewalls or network segmentation to restrict inbound access.

Generated by OpenCVE AI on August 1, 2026 at 09:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
Title Windows Admin Center (WAC) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows Admin Center
Weaknesses CWE-23
CPEs cpe:2.3:a:microsoft:windows_admin_center:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows Admin Center
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows Admin Center
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:27:01.531Z

Reserved: 2026-06-19T13:54:04.007Z

Link: CVE-2026-56196

cve-icon Vulnrichment

Updated: 2026-07-14T18:07:41.814Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:30:03Z

Weaknesses
  • CWE-23

    Relative Path Traversal