CVE-2026-42834
published 2026-05-20CVE-2026-42834: Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
PriorityP346high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.41%
32.9th percentile
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_admin_center | < 0.72.0.0 | 0.72.0.0 |
| microsoft | windows_admin_center_in_azure_portal | >= 1.0 < 0.72.0.0. | 0.72.0.0. |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Windows Admin Center in Azure Portal prior 0.72.0.0 link following
vuldb·2026-05-20·CVSS 7.8
CVE-2026-42834 [HIGH] Microsoft Windows Admin Center in Azure Portal prior 0.72.0.0 link following
A vulnerability classified as critical has been found in Microsoft Windows Admin Center in Azure Portal. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in link following.
This vulnerability is identified as CVE-2026-42834. The attack is only possible with local access. There is not any exploit available.
It is recommended to upgrade the affected component.
GHSA
GHSA-33pm-33cg-5576: Improper link resolution before file access ('link following') in Azure Portal Windows Admin Center allows an authorized attacker to elevate privilege
ghsa_unreviewed·2026-05-20
CVE-2026-42834 [HIGH] CWE-59 GHSA-33pm-33cg-5576: Improper link resolution before file access ('link following') in Azure Portal Windows Admin Center allows an authorized attacker to elevate privilege
Improper link resolution before file access ('link following') in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-20
Published