Junglewise Threat Intelligence

CVE-2026-57107: Microsoft Windows Admin Center improper authentication privilege escalation

CVE-2026-57107 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Admin Center. Vendors: Microsoft.

Executive brief

Windows Admin Center is a browser-based management tool used by IT administrators to manage Windows servers and infrastructure. A security flaw in this tool allows a user who already has basic access to the system to bypass authentication checks and gain higher-level administrative permissions. This could allow an unauthorized individual to take full control of the management console and the systems it oversees.

Technical details

An improper authentication vulnerability (CWE-287) exists in Microsoft Windows Admin Center. The flaw allows a locally authenticated attacker with low-level privileges to bypass authentication mechanisms within the management suite. By exploiting this weakness, the attacker can elevate their privileges to a higher level, potentially gaining full administrative control over the host and managed environment. The vulnerability affects versions starting from 1809.0 up to 2.7.4, and users are advised to apply the latest security updates from Microsoft.

Affected products

  • Microsoft Corporation Windows Admin Center 1809.0 to 2.7.4

Timeline

  • 2026-07-14: advisory: Initial disclosure by Microsoft and NVD.

References

Related threats