Junglewise Threat Intelligence

CVE-2026-35438: Microsoft Windows Admin Center privilege escalation via missing authorization

CVE-2026-35438 · Severity: high · CVSS 8.3 · Published 2026-05-12

Technologies: Microsoft Windows Admin Center. Vendors: Microsoft.

Executive brief

Windows Admin Center is a browser-based management tool used by IT administrators to manage Windows servers and infrastructure. A security flaw in this tool allows an attacker who already has basic access to the network to gain higher-level administrative permissions. This could allow an unauthorized user to take control of managed servers, potentially leading to data theft or service disruptions.

Technical details

A missing authorization vulnerability (CWE-862) exists in Microsoft Windows Admin Center. The flaw allows an authenticated attacker with low-level privileges to bypass authorization checks over the network. By exploiting this issue, the attacker can elevate their privileges to a higher level within the management console. This could lead to unauthorized configuration changes or full administrative control over the managed environment. Microsoft has addressed this in version 2511.

Affected products

  • Microsoft Windows Admin Center versions up to (excluding) 2511

Timeline

  • 2026-05-12: advisory: Initial disclosure by Microsoft
  • 2026-05-28: other: NVD analysis and CPE information added

References

Related threats