Microsoft Windows Admin Center vulnerabilities
20 known vulnerabilities affecting microsoft/windows_admin_center.
Total CVEs
20
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH14MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2026-56197P2HIGHCVSS 8.8fixed in 2606≥ 1809.0, < 2.7.42026-07-14
CVE-2026-56197 [HIGH] CWE-77 CVE-2026-56197: Improper neutralization of special elements used in a command ('command injection') in Windows Admin
Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.
nvd
CVE-2026-26119P2HIGHCVSS 8.8fixed in 2511≥ 1809.0, < 2.6.42026-02-17
CVE-2026-26119 [HIGH] CWE-287 CVE-2026-26119: Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-56169P2HIGHCVSS 8.8≥ 1809, < 2606≥ 1809.0, < 2.7.42026-07-14
CVE-2026-56169 [HIGH] CWE-287 CVE-2026-56169: Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-41086P3HIGHCVSS 8.8fixed in 2.6.72026-05-12
CVE-2026-41086 [HIGH] CWE-284 CVE-2026-41086: Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-56196P3HIGHCVSS 8.8fixed in 2606≥ 1809.0, < 2.7.42026-07-14
CVE-2026-56196 [HIGH] CWE-23 CVE-2026-56196: Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a
Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
nvd
CVE-2026-35438P3HIGHCVSS 8.3fixed in 2511≥ 1809.0, < 2.6.5.162026-05-12
CVE-2026-35438 [HIGH] CWE-862 CVE-2026-35438: Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges ov
Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2019-0813P3CRITICALCVSS 9.8fixed in 1809.5vunspecified2019-04-09
CVE-2019-0813 [CRITICAL] CVE-2019-0813: An elevation of privilege vulnerability exists when Windows Admin Center improperly impersonates ope
An elevation of privilege vulnerability exists when Windows Admin Center improperly impersonates operations in certain situations, aka 'Windows Admin Center Elevation of Privilege Vulnerability'.
nvd
CVE-2026-58631P3HIGHCVSS 7.8fixed in 2606≥ 1809.0, < 2.7.42026-07-14
CVE-2026-58631 [HIGH] CWE-285 CVE-2026-58631: Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally
Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
nvd
CVE-2026-42834P3HIGHCVSS 7.8fixed in 0.72.0.02026-05-20
CVE-2026-42834 [HIGH] CWE-59 CVE-2026-42834: Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-57107P3HIGHCVSS 7.8≥ 1809, < 2606≥ 1809.0, < 2.7.42026-07-14
CVE-2026-57107 [HIGH] CWE-287 CVE-2026-57107: Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56171P3HIGHCVSS 7.5fixed in 2606≥ 1809.0, < 2.7.42026-07-17
CVE-2026-56171 [HIGH] CWE-359 CVE-2026-56171: Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthori
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-64669P3HIGHCVSS 7.8fixed in 2511≥ 1809.0, < 2.6.5.162025-12-11
CVE-2025-64669 [HIGH] CWE-284 CVE-2025-64669: Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-23660P3HIGHCVSS 7.8fixed in 2.6.42026-03-10
CVE-2026-23660 [HIGH] CWE-284 CVE-2026-23660: Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevat
Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56185P3MEDIUMCVSS 6.5≥ 1809, < 2511≥ 1809.0, < 2.6.5.162026-07-14
CVE-2026-56185 [MEDIUM] CWE-94 CVE-2026-56185: Improper authentication in Windows Admin Center allows an authorized attacker to disclose informatio
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-20965P3HIGHCVSS 7.5fixed in 0.70.0.02026-01-13
CVE-2026-20965 [HIGH] CWE-347 CVE-2026-20965: Improper verification of cryptographic signature in Windows Admin Center allows an authorized attack
Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32196P4MEDIUMCVSS 6.1fixed in 2511≥ 1809.0, < 2.6.5.162026-04-14
CVE-2026-32196 [MEDIUM] CWE-79 CVE-2026-32196: Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admi
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2025-29819P4MEDIUMCVSS 6.2fixed in 0.45.0.0fixed in 2410+1 more2025-04-08
CVE-2025-29819 [MEDIUM] CWE-73 CVE-2025-29819: External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized at
External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-58643P4MEDIUMCVSS 6.1≥ 1809, < 2511≥ 1809.0, < 25112026-07-16
CVE-2026-58643 [MEDIUM] CWE-79 CVE-2026-58643: Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admi
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2021-27066P4MEDIUMCVSS 4.3≥ 1809.0, < publication2021-03-11
CVE-2021-27066 [MEDIUM] CVE-2021-27066: Windows Admin Center Security Feature Bypass Vulnerability
Windows Admin Center Security Feature Bypass Vulnerability
nvd
CVE-2023-29347HIGHCVSS 8.7≥ 1809.0, < 23062023-07-11
CVE-2023-29347 [HIGH] CWE-79 Windows Admin Center Spoofing Vulnerability
Windows Admin Center Spoofing Vulnerability
Windows Admin Center Spoofing Vulnerability
cvelistv5