cbcvebase.
CVE-2026-26183
published 2026-04-14

CVE-2026-26183: Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally.

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally.

Affected

12 ranges
VendorProductVersion rangeFixed in
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.260266.2.9200.26026
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.231326.3.9600.23132
microsoftwindows_server_2016< 10.0.14393.906010.0.14393.9060
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.906010.0.14393.9060
microsoftwindows_server_2019< 10.0.17763.864410.0.17763.8644
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.864410.0.17763.8644
microsoftwindows_server_2022< 10.0.20348.502010.0.20348.5020
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.502010.0.20348.5020
microsoftwindows_server_2022_23h2< 10.0.25398.227410.0.25398.2274
microsoftwindows_server_2025< 10.0.26100.3269010.0.26100.32690
microsoftwindows_server_2025>= 10.0.26100.0 < 10.0.26100.3269010.0.26100.32690