CVE-2026-56196
Windows Admin Center vulnerability analysis and mitigation

Overview

CVE-2026-56196 is a relative path traversal vulnerability in Microsoft Windows Admin Center that allows an authenticated, low-privileged attacker to execute arbitrary code remotely over a network. Disclosed on July 14, 2026, as part of Microsoft's Patch Tuesday release, the vulnerability affects Windows Admin Center versions from 1809.0 up to (excluding) 2.7.4 (CPE version identifier prior to build 2606). It carries a CVSS v3.1 base score of 8.8 (High), reflecting network-based exploitation with low privileges required and no user interaction needed (Microsoft MSRC, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-23 (Relative Path Traversal), meaning the application fails to properly neutralize path sequences (e.g., ../) in user-supplied input when constructing file system paths, allowing access to locations outside the intended restricted directory (GitHub Advisory). An attacker with low-level network access and valid credentials to the Windows Admin Center instance can craft malicious requests that traverse the file system and trigger code execution on the server. The attack requires no user interaction and has low complexity, making it straightforward to exploit once an attacker has authenticated access. No public proof-of-concept exploit code has been identified at this time (Microsoft MSRC).

Impact

Successful exploitation grants an authenticated attacker full remote code execution on the Windows Admin Center host, with high impact to confidentiality, integrity, and availability. Because Windows Admin Center is typically used to manage Windows Server infrastructure, a compromised instance could serve as a pivot point for lateral movement across managed servers and workloads. Sensitive administrative credentials, configuration data, and server management capabilities could all be exposed or abused (Microsoft MSRC, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet- or network-facing Windows Admin Center instances (versions prior to 2.7.4 / build 2606) using network scanning tools or service discovery. Windows Admin Center typically listens on port 443 (HTTPS).
  2. Authentication: Obtain valid low-privileged credentials for the Windows Admin Center instance through phishing, credential stuffing, or other means, as the vulnerability requires an authenticated session.
  3. Craft malicious request: Construct an HTTP request to a Windows Admin Center API endpoint that accepts file path parameters, embedding relative path traversal sequences (e.g., ../../) to escape the intended directory boundary.
  4. Trigger code execution: Submit the crafted request so that the traversed path resolves to a location where attacker-controlled content can be executed or where a sensitive system resource can be manipulated to achieve code execution on the server.
  5. Post-exploitation: Use the resulting code execution to establish persistence, harvest credentials, or pivot to managed Windows Server infrastructure accessible through the Admin Center (Microsoft MSRC, GitHub Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTPS requests to Windows Admin Center (default port 443) containing path traversal sequences (../, ..%2F, %2e%2e%2f) in URL parameters or request bodies; unexpected outbound connections from the Admin Center host to external IPs.
  • Logs: Windows Admin Center application logs showing access to file paths outside expected application directories; IIS or SME (Server Management Experience) logs with anomalous path strings or HTTP 500 errors triggered by malformed path inputs.
  • File System: Unexpected files written outside the Windows Admin Center installation directory; new scripts, executables, or web shells in system directories accessible by the Admin Center service account.
  • Process: Unusual child processes spawned by the Windows Admin Center service (e.g., cmd.exe, powershell.exe, wscript.exe) with unexpected arguments or network connections; new scheduled tasks or services created under the Admin Center service account context.

Mitigation and workarounds

Microsoft has released a patch addressing this vulnerability; administrators should upgrade Windows Admin Center to version 2.7.4 (build 2606) or later as the primary remediation (Microsoft MSRC). As a compensating control, restrict network access to the Windows Admin Center portal to only authorized management networks and users, reducing the attack surface for authenticated exploitation. Enforce strong authentication (e.g., multi-factor authentication) for all Windows Admin Center accounts to raise the bar for attackers seeking to meet the low-privilege authentication prerequisite.

Community reactions

CVE-2026-56196 was disclosed as part of Microsoft's July 2026 Patch Tuesday, which addressed a record 570 vulnerabilities. Security news outlets including GBHackers and CyberSecurityNews covered the broader Patch Tuesday release, noting the scale of the update (GBHackers, CyberSecurityNews). No specific researcher commentary or notable social media discussion focused exclusively on CVE-2026-56196 has been identified at this time.

Additional resources


SourceThis report was generated using AI

Related Windows Admin Center vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56197HIGH8.8
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 14, 2026
CVE-2026-56196HIGH8.8
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 14, 2026
CVE-2026-58631HIGH7.8
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 14, 2026
CVE-2026-56171HIGH7.5
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 17, 2026
CVE-2026-58643MEDIUM6.1
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management