Description
Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper authorization in Microsoft Windows Admin Center allows an authorized attacker to execute code locally on the device. The flaw is classified as CWE‑285 and permits running arbitrary code with the privileges of the authenticated session.

Affected Systems

The vulnerability applies to Microsoft Windows Admin Center. All deployments of Windows Admin Center that have not applied the latest security update may be affected; no specific version range is provided.

Risk and Exploitability

The CVSS score of 7.8 indicates a high‑severity vulnerability, while the EPSS score is less than 1 % and the issue is not listed in CISA’s KEV catalog. Exploitation requires an attacker to have authenticated access to the WAC portal; the missing authorization enables the attacker to execute arbitrary code locally on the target machine. Because the attack vector depends on existing privileges, widespread exploitation is limited to environments where administrators have not been restricted from the portal.

Generated by OpenCVE AI on July 31, 2026 at 09:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Windows Admin Center update that fixes the improper authorization issue from Microsoft.
  • Restrict access to the Windows Admin Center portal to trusted administrators and enforce least‑privilege principles.
  • Segment or firewall the WAC services to limit exposure to attackers.

Generated by OpenCVE AI on July 31, 2026 at 09:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
Title Windows Admin Center (WAC) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows Admin Center
Weaknesses CWE-285
CPEs cpe:2.3:a:microsoft:windows_admin_center:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows Admin Center
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows Admin Center
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:23:10.998Z

Reserved: 2026-07-01T21:14:44.616Z

Link: CVE-2026-58631

cve-icon Vulnrichment

Updated: 2026-07-14T17:45:05.471Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:15:06Z

Weaknesses