CVE-2026-20967Improper Input Validation in Microsoft System Center Operations Manager 2019

Severity
8.8HIGHNVD
EPSS
0.1%
top 69.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 10

Description

Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

CVEListV5microsoft/system_center_operations_manager_201910.19.010.19.10658.0
CVEListV5microsoft/system_center_operations_manager_202210.22.010.22.11951.0
CVEListV5microsoft/system_center_operations_manager_20251.0.010.25.10377.0

🔴Vulnerability Details

2
GHSA
GHSA-8gfh-97q4-r32h: Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network2026-03-10
CVEList
System Center Operations Manager (SCOM) Elevation of Privilege Vulnerability2026-03-10

📋Vendor Advisories

1
Microsoft
System Center Operations Manager (SCOM) Elevation of Privilege Vulnerability2026-03-10
CVE-2026-20967 — Improper Input Validation in Microsoft | cvebase