
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-56171 is an information disclosure vulnerability classified as "Exposure of Private Personal Information to an Unauthorized Actor" (CWE-359) affecting Microsoft's Windows RDP ecosystem. It allows an unauthorized network attacker to disclose private personal information from affected systems. The vulnerability affects Microsoft Remote Desktop Web Client versions from 2.0.0.0 up to (but not including) 2.1.65.2, and Windows Admin Center versions from 1809.0 up to (but not including) 2.7.4. It was publicly disclosed on July 16, 2026, with NVD publication on July 17, 2026. The CVSS v3.1 base score is 7.5 (High) per Microsoft/NVD, and 7.1 (High) per ENISA/GitHub Advisory (Microsoft MSRC, Github Advisory).
The root cause is classified as CWE-359 (Exposure of Private Personal Information to an Unauthorized Actor), indicating that the affected components — Remote Desktop Web Client and Windows Admin Center — fail to properly restrict access to private personal information transmitted or processed over the network. The attack vector is network-based with low attack complexity and no privileges required; however, the GitHub Advisory notes that user interaction is required in some scoring interpretations, suggesting the vulnerability may involve a scenario where a user's session or data is exposed to a network-accessible attacker. No public technical write-ups or proof-of-concept code detailing the precise exploitation mechanism have been published as of the disclosure date (Github Advisory, Microsoft MSRC).
Successful exploitation results in the unauthorized disclosure of private personal information over a network, with a high confidentiality impact and no direct integrity or availability impact. Affected assets include deployments of Microsoft Remote Desktop Web Client and Windows Admin Center, which are commonly used in enterprise environments for remote administration and access. The exposure of personal or session-related data could facilitate further attacks such as credential theft, session hijacking, or targeted phishing, depending on the nature of the disclosed information (Microsoft MSRC, Github Advisory).
Microsoft has released patched versions addressing this vulnerability. Organizations should update Remote Desktop Web Client to version 2.1.65.2 or later and Windows Admin Center to version 2606 (2.7.4) or later. No specific configuration-based workarounds have been publicly documented; upgrading to the fixed versions is the recommended remediation. Administrators should prioritize patching internet-facing or enterprise-critical deployments of these components (Microsoft MSRC, Github Advisory).
Security researcher Will Dormann (@wdormann) noted the vulnerability on Infosec.Exchange shortly after disclosure, and VulnDB published an entry tracking community interest. General community sentiment appears measured given the lack of public exploit code and the moderate EPSS score. No major media coverage or vendor statements beyond the official Microsoft MSRC advisory have been identified (Microsoft MSRC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."