Junglewise Threat Intelligence

CVE-2026-56197: Microsoft Windows Admin Center command injection

CVE-2026-56197 · Severity: high · CVSS 8.8 · Published 2026-07-14

Technologies: Microsoft Windows Admin Center. Vendors: Microsoft.

Executive brief

Windows Admin Center is a browser-based management tool used by IT administrators to manage Windows servers and infrastructure. A security flaw allows an authorized user to execute unauthorized commands on the system over the network. This could lead to a complete takeover of the managed servers, potentially resulting in data theft or significant operational disruption.

Technical details

A command injection vulnerability (CWE-77) exists in Microsoft Windows Admin Center due to improper neutralization of special elements used in a command. An attacker with low-privileged authorized access can exploit this flaw over the network without any user interaction. Successful exploitation allows for remote code execution with high impact on confidentiality, integrity, and availability. Microsoft has addressed this issue in Windows Admin Center versions starting from 2.7.4.

Affected products

  • Microsoft Windows Admin Center 1809.0 to 2.7.4

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats