PT-2026-20332 · Microsoft · Windows Admin Center

·

CVE-2026-26119

·

Published

2026-02-17

·

Updated

2026-08-27

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows Admin Center versions prior to 2511
Description Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. An authenticated low-privileged user can gain the rights of the account running the Windows Admin Center service. Because Windows Admin Center serves as a centralized control plane for managing servers, clusters, and Active Directory-joined systems, this flaw could potentially lead to full domain compromise under certain conditions.
Recommendations Update Windows Admin Center to version 2511.

Fix

LPE

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03415
CVE-2026-26119

Affected Products

Windows Admin Center