
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26183 is a local privilege escalation vulnerability caused by improper access control in the Windows RPC API. It allows an authorized (low-privileged) local attacker to elevate privileges to SYSTEM level without requiring user interaction. The vulnerability affects multiple Windows Server versions including Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2022 23H2, and 2025. It was disclosed and patched on April 14, 2026, as part of Microsoft's April 2026 Patch Tuesday security updates. The CVSS v3.1 base score is 7.8 (High) (Microsoft MSRC).
The root cause is classified as CWE-284 (Improper Access Control) within the Windows Remote Procedure Call (RPC) API. An attacker with low-privileged local access can abuse insufficient access control checks in the RPC API to escalate their privileges to SYSTEM level. The attack vector is local, requires low privileges, has low attack complexity, and requires no user interaction, making it straightforward to exploit once local access is obtained (Microsoft MSRC). No public proof-of-concept code has been identified at this time (Feedly).
Successful exploitation grants a low-privileged local attacker full SYSTEM-level control over the affected Windows Server system, resulting in high confidentiality, integrity, and availability impacts. An attacker achieving SYSTEM privileges can read or exfiltrate sensitive data, modify or destroy system files and configurations, disable security controls, and establish persistent access. This level of compromise also facilitates lateral movement within a network environment, particularly in domain-joined server scenarios (Microsoft MSRC).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.055%, indicating a low current probability of exploitation in the wild. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has assigned detection ID 92370 for this vulnerability, enabling scanner-based identification of affected systems (Feedly).
Microsoft released security updates on April 14, 2026, addressing this vulnerability across all affected Windows Server versions. Organizations should apply the following patched builds immediately:
As interim mitigations, restrict local access to Windows servers to only authorized users, monitor for suspicious privilege escalation activity, and consider restricting RPC access where operationally feasible (Microsoft MSRC).
The vulnerability was covered as part of broader April 2026 Patch Tuesday roundups by several security vendors and researchers. Zero Day Initiative (ZDI), Rapid7, Sophos, Lansweeper, and NSFOCUS all included CVE-2026-26183 in their Patch Tuesday analyses, noting it as a notable local privilege escalation affecting Windows Server infrastructure (ZDI, Rapid7, Sophos). Korean CERT (KR-CERT/BOHO) also issued advisories referencing this CVE. No significant controversy or unusual community sentiment was noted beyond standard patch urgency recommendations.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."