Description
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-07-16
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Windows Admin Center contains an improper neutralization of input during web page generation that qualifies as a cross‑site scripting flaw. This weakness allows an unauthorized user to inject specially crafted content into a page that the service renders. The injected payload can make the application display a page that appears to originate from a trusted administrator, effectively spoofing a legitimate user. If successful, the attacker can masquerade as that user over the network, potentially gaining access to administrative functions or confidential information.

Affected Systems

All installations of Microsoft Windows Admin Center that have not applied the latest updates are susceptible. The affected software is the Windows Admin Center product; any deployment exposing the web portal to external or internal networks carries risk if not patched.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. An EPSS score of less than 1 % suggests a low likelihood that this vulnerability will be widely exploited in the short term. The vulnerability is not present in the CISA KEV catalog. Exploitation requires an attacker to acquire a web session that can reach the Admin Center portal, then supply malicious input to a page‑generation component. Based on the description, it is inferred that the attack vector is remote, through the web interface, and is mitigated by limiting network access and applying the vendor patch.

Generated by OpenCVE AI on July 31, 2026 at 01:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Windows Admin Center update via the Microsoft Update portal or the official download location
  • Limit inbound traffic to the Windows Admin Center web portal to approved IP ranges or VPN endpoints to reduce attack surface
  • Implement a strict Content‑Security‑Policy header or a web application firewall to block execution of injected scripts

Generated by OpenCVE AI on July 31, 2026 at 01:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 18 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
Title Windows Admin Center Spoofing Vulnerability
First Time appeared Microsoft
Microsoft windows Admin Center
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:windows_admin_center:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows Admin Center
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows Admin Center
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:53:57.164Z

Reserved: 2026-07-01T21:14:44.618Z

Link: CVE-2026-58643

cve-icon Vulnrichment

Updated: 2026-07-18T03:20:18.907Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:15:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')