Junglewise Threat Intelligence

CVE-2026-56185: Microsoft Windows Admin Center improper authentication

CVE-2026-56185 · Severity: medium · CVSS 6.5 · Published 2026-07-14

Technologies: Microsoft Windows Admin Center. Vendors: Microsoft.

Executive brief

Microsoft Windows Admin Center, a management tool used by IT administrators to manage Windows servers and PCs, contains a security flaw. An authorized user on the network could exploit this weakness to access sensitive information they are not supposed to see. This could lead to the exposure of internal system data or configuration details, potentially aiding further attacks on the infrastructure.

Technical details

An improper authentication vulnerability exists in Microsoft Windows Admin Center. The flaw, categorized under CWE-287 (Improper Authentication) and CWE-94 (Improper Control of Generation of Code), allows an attacker with low-privileged credentials to bypass certain security checks over the network. By exploiting this issue, an authenticated attacker can gain unauthorized access to sensitive information. The vulnerability affects versions starting from 1809.0 up to 2.6.5.16. Users are advised to update to the latest version provided by Microsoft to mitigate this risk.

Affected products

  • Microsoft Windows Admin Center 1809.0 to 2.6.5.16

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats