CVE-2026-56197
Windows Admin Center vulnerability analysis and mitigation

Overview

CVE-2026-56197 is a command injection vulnerability in Microsoft Windows Admin Center that allows an authorized, low-privileged attacker to execute arbitrary code remotely over a network. It was disclosed on July 14, 2026, as part of Microsoft's Patch Tuesday update cycle, and affects Windows Admin Center versions from 1809.0 up to (but not including) 2.7.4 (build 2606). The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (MSRC, Github Advisory).

Technical details

The root cause is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command), meaning Windows Admin Center fails to adequately sanitize user-supplied input before incorporating it into system commands. An authenticated attacker with low-level privileges can craft malicious input containing command delimiters or special characters that alter the intended command execution flow, resulting in arbitrary code execution on the server hosting Windows Admin Center. The attack requires no user interaction and is conducted entirely over the network, making it straightforward to exploit once an attacker has valid credentials (MSRC, Github Advisory).

Impact

Successful exploitation grants an attacker the ability to execute arbitrary code on the Windows Admin Center host system, resulting in high impact to confidentiality, integrity, and availability. Because Windows Admin Center is a server management platform with broad administrative reach over connected Windows infrastructure, a compromised instance could serve as a pivot point for lateral movement across managed servers and workloads. The technical impact is assessed as "total" by CISA-ADP, meaning an attacker could fully compromise the affected system (MSRC).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible Windows Admin Center instances running versions prior to 2.7.4 (build 2606) using network scanning tools or service discovery.
  2. Obtain valid credentials: Acquire low-privileged user credentials for the Windows Admin Center instance through phishing, credential stuffing, or other means, as the vulnerability requires authentication.
  3. Identify injectable parameter: Interact with Windows Admin Center's web interface or API to locate input fields or API endpoints that pass user-supplied data to underlying system commands without adequate sanitization.
  4. Craft malicious payload: Construct input containing command injection characters (e.g., &, |, ;, backticks, or newline sequences) followed by attacker-controlled commands to be executed on the server.
  5. Submit payload: Send the crafted request to the vulnerable endpoint via the Windows Admin Center web interface or its REST API.
  6. Achieve code execution: The injected command executes on the Windows Admin Center host with the privileges of the service account, enabling reverse shell establishment, credential harvesting, or further lateral movement across managed infrastructure (MSRC, Github Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the Windows Admin Center host to external or unusual internal IP addresses; anomalous API calls to Windows Admin Center endpoints with unusually long or specially-encoded parameter values.
  • Logs: Windows Admin Center application logs showing requests with command delimiter characters (&, |, ;, backticks) in input fields; Windows Event Logs (Security, System) recording unexpected process creation events originating from the Windows Admin Center service account.
  • Process: Unusual child processes spawned by the Windows Admin Center service process (e.g., cmd.exe, powershell.exe, net.exe, curl.exe) with suspicious arguments; unexpected scheduled tasks or services created under the Windows Admin Center service account context.
  • File System: New or modified scripts, executables, or web shells placed in the Windows Admin Center installation directory or temp folders; unexpected changes to system configuration files.

Mitigation and workarounds

Microsoft has released a patch addressing this vulnerability; administrators should update Windows Admin Center to version 2.7.4 (build 2606) or later immediately (MSRC). As a compensating control, restrict network access to the Windows Admin Center portal to only authorized administrators using firewall rules or network segmentation, reducing the attack surface. Additionally, monitor Windows Admin Center logs and Windows Event Logs for suspicious command patterns and audit all user accounts with access to the platform.

Community reactions

CVE-2026-56197 was covered as part of broader reporting on Microsoft's July 2026 Patch Tuesday, which addressed a record 570 vulnerabilities. Security news outlets including GBHackers and CyberSecurityNews highlighted the scale of the July 2026 update cycle, though this specific CVE did not receive individual prominent coverage. No notable independent researcher commentary or vendor statements beyond the MSRC advisory have been identified for this vulnerability.

Additional resources


SourceThis report was generated using AI

Related Windows Admin Center vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56197HIGH8.8
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 14, 2026
CVE-2026-56196HIGH8.8
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 14, 2026
CVE-2026-58631HIGH7.8
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 14, 2026
CVE-2026-56171HIGH7.5
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 17, 2026
CVE-2026-58643MEDIUM6.1
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management