Microsoft · Windows Admin Center · CVE-2026-2096
**Name of the Vulnerable Software and Affected Versions**
Agentflow versions (affected versions not specified)
Windows Admin Center versions (affected versions not specified)
**Description**
Agentflow, developed by Flowring, exhibits a Missing Authentication issue. This allows unauthenticated remote attackers to perform actions on the database, including reading, modifying, and deleting its contents, through a specific functionality. A separate high-severity flaw exists in the Azure SSO implementation of Windows Admin Center, potentially allowing a local administrator on a single machine to achieve tenant-wide remote code execution.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.