Junglewise Threat Intelligence

CVE-2026-56196: Microsoft Windows Admin Center path traversal remote code execution

CVE-2026-56196 · Severity: high · CVSS 8.8 · Published 2026-07-14

Technologies: Microsoft Windows Admin Center. Vendors: Microsoft.

Executive brief

Windows Admin Center is a management tool used by IT administrators to manage Windows servers and infrastructure. A security flaw allows an authorized user to bypass file access restrictions and execute malicious code on the system. This could lead to a full takeover of the management console and the servers it controls, potentially resulting in data theft or service disruption.

Technical details

A relative path traversal vulnerability (CWE-23) exists in Microsoft Windows Admin Center. The flaw allows an authenticated attacker with low privileges to submit specially crafted requests over the network to access files or directories outside of the intended scope. By exploiting this path traversal, the attacker can achieve remote code execution on the target system. The vulnerability affects versions starting from 1809.0 up to 2.7.4, and users are advised to update to the latest available version from Microsoft.

Affected products

  • Microsoft Windows Admin Center 1809.0 to 2.7.4

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats