Junglewise Threat Intelligence

CVE-2026-58643: Microsoft Windows Admin Center cross-site scripting

CVE-2026-58643 · Severity: medium · CVSS 6.1 · Published 2026-07-16

Technologies: Microsoft Windows Admin Center. Vendors: Microsoft.

Executive brief

Windows Admin Center, a browser-based management tool for Windows servers and clusters, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the interface. If an administrator visits a specially crafted link, an attacker could impersonate the user or perform unauthorized actions within the management console. This could lead to unauthorized configuration changes or the theft of sensitive session information.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Microsoft Windows Admin Center due to improper neutralization of user-supplied input during web page generation. An unauthenticated, remote attacker can exploit this by tricking a legitimate user into clicking a malicious link or visiting a compromised website. Successful exploitation allows the attacker to execute arbitrary script code in the context of the victim's browser session, potentially leading to session hijacking, unauthorized data access, or spoofing of administrative actions. The vulnerability is tracked as CWE-79 and affects versions starting from 1809.0 up to 2511.

Affected products

  • Microsoft Windows Admin Center 1809.0 to 2511

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory

References

Related threats