
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-56197 is a command injection vulnerability in Microsoft Windows Admin Center that allows an authorized, low-privileged attacker to execute arbitrary code remotely over a network. It was disclosed on July 14, 2026, as part of Microsoft's Patch Tuesday update cycle, and affects Windows Admin Center versions from 1809.0 up to (but not including) 2.7.4 (build 2606). The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (MSRC, Github Advisory).
The root cause is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command), meaning Windows Admin Center fails to adequately sanitize user-supplied input before incorporating it into system commands. An authenticated attacker with low-level privileges can craft malicious input containing command delimiters or special characters that alter the intended command execution flow, resulting in arbitrary code execution on the server hosting Windows Admin Center. The attack requires no user interaction and is conducted entirely over the network, making it straightforward to exploit once an attacker has valid credentials (MSRC, Github Advisory).
Successful exploitation grants an attacker the ability to execute arbitrary code on the Windows Admin Center host system, resulting in high impact to confidentiality, integrity, and availability. Because Windows Admin Center is a server management platform with broad administrative reach over connected Windows infrastructure, a compromised instance could serve as a pivot point for lateral movement across managed servers and workloads. The technical impact is assessed as "total" by CISA-ADP, meaning an attacker could fully compromise the affected system (MSRC).
&, |, ;, backticks, or newline sequences) followed by attacker-controlled commands to be executed on the server.&, |, ;, backticks) in input fields; Windows Event Logs (Security, System) recording unexpected process creation events originating from the Windows Admin Center service account.cmd.exe, powershell.exe, net.exe, curl.exe) with suspicious arguments; unexpected scheduled tasks or services created under the Windows Admin Center service account context.Microsoft has released a patch addressing this vulnerability; administrators should update Windows Admin Center to version 2.7.4 (build 2606) or later immediately (MSRC). As a compensating control, restrict network access to the Windows Admin Center portal to only authorized administrators using firewall rules or network segmentation, reducing the attack surface. Additionally, monitor Windows Admin Center logs and Windows Event Logs for suspicious command patterns and audit all user accounts with access to the platform.
CVE-2026-56197 was covered as part of broader reporting on Microsoft's July 2026 Patch Tuesday, which addressed a record 570 vulnerabilities. Security news outlets including GBHackers and CyberSecurityNews highlighted the scale of the July 2026 update cycle, though this specific CVE did not receive individual prominent coverage. No notable independent researcher commentary or vendor statements beyond the MSRC advisory have been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."