cbcvebase.

Microsoft Windows Admin Center vulnerabilities

20 known vulnerabilities affecting microsoft/windows_admin_center.

Total CVEs
20
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH14MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2026-56197P2HIGHCVSS 8.8fixed in 2606≥ 1809.0, < 2.7.42026-07-14
CVE-2026-56197 [HIGH] CWE-77 CVE-2026-56197: Improper neutralization of special elements used in a command ('command injection') in Windows Admin Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.
nvd
CVE-2026-26119P2HIGHCVSS 8.8fixed in 2511≥ 1809.0, < 2.6.42026-02-17
CVE-2026-26119 [HIGH] CWE-287 CVE-2026-26119: Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-56169P2HIGHCVSS 8.8≥ 1809, < 2606≥ 1809.0, < 2.7.42026-07-14
CVE-2026-56169 [HIGH] CWE-287 CVE-2026-56169: Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-41086P3HIGHCVSS 8.8fixed in 2.6.72026-05-12
CVE-2026-41086 [HIGH] CWE-284 CVE-2026-41086: Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-56196P3HIGHCVSS 8.8fixed in 2606≥ 1809.0, < 2.7.42026-07-14
CVE-2026-56196 [HIGH] CWE-23 CVE-2026-56196: Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
nvd
CVE-2026-35438P3HIGHCVSS 8.3fixed in 2511≥ 1809.0, < 2.6.5.162026-05-12
CVE-2026-35438 [HIGH] CWE-862 CVE-2026-35438: Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges ov Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2019-0813P3CRITICALCVSS 9.8fixed in 1809.5vunspecified2019-04-09
CVE-2019-0813 [CRITICAL] CVE-2019-0813: An elevation of privilege vulnerability exists when Windows Admin Center improperly impersonates ope An elevation of privilege vulnerability exists when Windows Admin Center improperly impersonates operations in certain situations, aka 'Windows Admin Center Elevation of Privilege Vulnerability'.
nvd
CVE-2026-58631P3HIGHCVSS 7.8fixed in 2606≥ 1809.0, < 2.7.42026-07-14
CVE-2026-58631 [HIGH] CWE-285 CVE-2026-58631: Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
nvd
CVE-2026-42834P3HIGHCVSS 7.8fixed in 0.72.0.02026-05-20
CVE-2026-42834 [HIGH] CWE-59 CVE-2026-42834: Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-57107P3HIGHCVSS 7.8≥ 1809, < 2606≥ 1809.0, < 2.7.42026-07-14
CVE-2026-57107 [HIGH] CWE-287 CVE-2026-57107: Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56171P3HIGHCVSS 7.5fixed in 2606≥ 1809.0, < 2.7.42026-07-17
CVE-2026-56171 [HIGH] CWE-359 CVE-2026-56171: Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthori Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-64669P3HIGHCVSS 7.8fixed in 2511≥ 1809.0, < 2.6.5.162025-12-11
CVE-2025-64669 [HIGH] CWE-284 CVE-2025-64669: Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-23660P3HIGHCVSS 7.8fixed in 2.6.42026-03-10
CVE-2026-23660 [HIGH] CWE-284 CVE-2026-23660: Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevat Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56185P3MEDIUMCVSS 6.5≥ 1809, < 2511≥ 1809.0, < 2.6.5.162026-07-14
CVE-2026-56185 [MEDIUM] CWE-94 CVE-2026-56185: Improper authentication in Windows Admin Center allows an authorized attacker to disclose informatio Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-20965P3HIGHCVSS 7.5fixed in 0.70.0.02026-01-13
CVE-2026-20965 [HIGH] CWE-347 CVE-2026-20965: Improper verification of cryptographic signature in Windows Admin Center allows an authorized attack Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32196P4MEDIUMCVSS 6.1fixed in 2511≥ 1809.0, < 2.6.5.162026-04-14
CVE-2026-32196 [MEDIUM] CWE-79 CVE-2026-32196: Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admi Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2025-29819P4MEDIUMCVSS 6.2fixed in 0.45.0.0fixed in 2410+1 more2025-04-08
CVE-2025-29819 [MEDIUM] CWE-73 CVE-2025-29819: External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized at External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-58643P4MEDIUMCVSS 6.1≥ 1809, < 2511≥ 1809.0, < 25112026-07-16
CVE-2026-58643 [MEDIUM] CWE-79 CVE-2026-58643: Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admi Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2021-27066P4MEDIUMCVSS 4.3≥ 1809.0, < publication2021-03-11
CVE-2021-27066 [MEDIUM] CVE-2021-27066: Windows Admin Center Security Feature Bypass Vulnerability Windows Admin Center Security Feature Bypass Vulnerability
nvd
CVE-2023-29347HIGHCVSS 8.7≥ 1809.0, < 23062023-07-11
CVE-2023-29347 [HIGH] CWE-79 Windows Admin Center Spoofing Vulnerability Windows Admin Center Spoofing Vulnerability Windows Admin Center Spoofing Vulnerability
cvelistv5
Microsoft Windows Admin Center vulnerabilities | cvebase