
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-56196 is a relative path traversal vulnerability in Microsoft Windows Admin Center that allows an authenticated, low-privileged attacker to execute arbitrary code remotely over a network. Disclosed on July 14, 2026, as part of Microsoft's Patch Tuesday release, the vulnerability affects Windows Admin Center versions from 1809.0 up to (excluding) 2.7.4 (CPE version identifier prior to build 2606). It carries a CVSS v3.1 base score of 8.8 (High), reflecting network-based exploitation with low privileges required and no user interaction needed (Microsoft MSRC, GitHub Advisory).
The vulnerability is classified as CWE-23 (Relative Path Traversal), meaning the application fails to properly neutralize path sequences (e.g., ../) in user-supplied input when constructing file system paths, allowing access to locations outside the intended restricted directory (GitHub Advisory). An attacker with low-level network access and valid credentials to the Windows Admin Center instance can craft malicious requests that traverse the file system and trigger code execution on the server. The attack requires no user interaction and has low complexity, making it straightforward to exploit once an attacker has authenticated access. No public proof-of-concept exploit code has been identified at this time (Microsoft MSRC).
Successful exploitation grants an authenticated attacker full remote code execution on the Windows Admin Center host, with high impact to confidentiality, integrity, and availability. Because Windows Admin Center is typically used to manage Windows Server infrastructure, a compromised instance could serve as a pivot point for lateral movement across managed servers and workloads. Sensitive administrative credentials, configuration data, and server management capabilities could all be exposed or abused (Microsoft MSRC, GitHub Advisory).
../../) to escape the intended directory boundary.../, ..%2F, %2e%2e%2f) in URL parameters or request bodies; unexpected outbound connections from the Admin Center host to external IPs.cmd.exe, powershell.exe, wscript.exe) with unexpected arguments or network connections; new scheduled tasks or services created under the Admin Center service account context.Microsoft has released a patch addressing this vulnerability; administrators should upgrade Windows Admin Center to version 2.7.4 (build 2606) or later as the primary remediation (Microsoft MSRC). As a compensating control, restrict network access to the Windows Admin Center portal to only authorized management networks and users, reducing the attack surface for authenticated exploitation. Enforce strong authentication (e.g., multi-factor authentication) for all Windows Admin Center accounts to raise the bar for attackers seeking to meet the low-privilege authentication prerequisite.
CVE-2026-56196 was disclosed as part of Microsoft's July 2026 Patch Tuesday, which addressed a record 570 vulnerabilities. Security news outlets including GBHackers and CyberSecurityNews covered the broader Patch Tuesday release, noting the scale of the update (GBHackers, CyberSecurityNews). No specific researcher commentary or notable social media discussion focused exclusively on CVE-2026-56196 has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."