PT-2026-58695 · Microsoft · Configuration Manager

CVE-2026-47301

·

Published

2026-07-14

·

Updated

2026-09-01

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Configuration Manager version 2509
Description Improper access control allows an authorized attacker to elevate privileges over a network. This issue can be part of an exploit chain involving broken access, CAB arbitrary-write path traversal, certificate verification bypass, and DLL hijacking to achieve SYSTEM-level code execution. DLL hijacking is a technique where a malicious library is loaded instead of the intended one.
Recommendations Update Microsoft Configuration Manager version 2509 to the latest patched version.

Exploit

Fix

RCE

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11890
CVE-2026-47301

Affected Products

Configuration Manager