PT-2026-20332 · Microsoft · Windows Admin Center

Andrea Pierini

+1

·

Published

2026-02-17

·

Updated

2026-04-15

·

CVE-2026-26119

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows Admin Center versions prior to 2511 Description An improper authentication issue exists in Windows Admin Center, potentially allowing an authorized attacker to elevate privileges on a network. The vulnerability, identified as CVE-2026-26119, has a CVSS score of 8.8 (High severity). An attacker with low-level access credentials could exploit this flaw to gain the rights of the user running the application, potentially leading to broad administrative control and even domain compromise under certain conditions. The vulnerability stems from flawed session handling or token validation. While there are no reports of active exploitation, Microsoft rates the vulnerability as having a “high likelihood of exploitation”. Recommendations Update Windows Admin Center to version 2511 or later.

Fix

LPE

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2026-03415
CVE-2026-26119

Affected Products

Windows Admin Center