CVE-2026-26183
vulnerability analysis and mitigation

Overview

CVE-2026-26183 is a local privilege escalation vulnerability caused by improper access control in the Windows RPC API. It allows an authorized (low-privileged) local attacker to elevate privileges to SYSTEM level without requiring user interaction. The vulnerability affects multiple Windows Server versions including Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2022 23H2, and 2025. It was disclosed and patched on April 14, 2026, as part of Microsoft's April 2026 Patch Tuesday security updates. The CVSS v3.1 base score is 7.8 (High) (Microsoft MSRC).

Technical details

The root cause is classified as CWE-284 (Improper Access Control) within the Windows Remote Procedure Call (RPC) API. An attacker with low-privileged local access can abuse insufficient access control checks in the RPC API to escalate their privileges to SYSTEM level. The attack vector is local, requires low privileges, has low attack complexity, and requires no user interaction, making it straightforward to exploit once local access is obtained (Microsoft MSRC). No public proof-of-concept code has been identified at this time (Feedly).

Impact

Successful exploitation grants a low-privileged local attacker full SYSTEM-level control over the affected Windows Server system, resulting in high confidentiality, integrity, and availability impacts. An attacker achieving SYSTEM privileges can read or exfiltrate sensitive data, modify or destroy system files and configurations, disable security controls, and establish persistent access. This level of compromise also facilitates lateral movement within a network environment, particularly in domain-joined server scenarios (Microsoft MSRC).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.055%, indicating a low current probability of exploitation in the wild. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has assigned detection ID 92370 for this vulnerability, enabling scanner-based identification of affected systems (Feedly).

Mitigation and workarounds

Microsoft released security updates on April 14, 2026, addressing this vulnerability across all affected Windows Server versions. Organizations should apply the following patched builds immediately:

  • Windows Server 2025: 10.0.26100.32690 or later
  • Windows Server 2022 23H2: 10.0.25398.2274 or later
  • Windows Server 2022: 10.0.20348.5020 or later
  • Windows Server 2019: 10.0.17763.8644 or later
  • Windows Server 2016: 10.0.14393.9060 or later
  • Windows Server 2012 R2: 6.3.9600.23132 or later
  • Windows Server 2012: 6.2.9200.26026 or later

As interim mitigations, restrict local access to Windows servers to only authorized users, monitor for suspicious privilege escalation activity, and consider restricting RPC access where operationally feasible (Microsoft MSRC).

Community reactions

The vulnerability was covered as part of broader April 2026 Patch Tuesday roundups by several security vendors and researchers. Zero Day Initiative (ZDI), Rapid7, Sophos, Lansweeper, and NSFOCUS all included CVE-2026-26183 in their Patch Tuesday analyses, noting it as a notable local privilege escalation affecting Windows Server infrastructure (ZDI, Rapid7, Sophos). Korean CERT (KR-CERT/BOHO) also issued advisories referencing this CVE. No significant controversy or unusual community sentiment was noted beyond standard patch urgency recommendations.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management