cbcvebase.
CVE-2026-47301
published 2026-07-14

CVE-2026-47301: Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.78%
53.9th percentile
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_configuration_manager>= 1.0.0 < 5.0.9135.10315.0.9135.1031
microsoftmicrosoft_configuration_manager_2509>= 1.0.0 < 5.0.9141.10305.0.9141.1030
microsoftmicrosoft_configuration_manager_2603>= 1.0.0 < 5.0.9146.10215.0.9146.1021
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.