
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-58631 is an improper authorization vulnerability in Microsoft Windows Admin Center that allows a locally authenticated, low-privileged attacker to execute arbitrary code on the affected system. It was published on July 14, 2026, as part of Microsoft's July 2026 Patch Tuesday release. Affected versions span from 1809.0 up to (but not including) version 2.7.4 (also referenced as build 2606). The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).
The root cause is classified as CWE-285 (Improper Authorization), meaning Windows Admin Center fails to properly enforce authorization controls for certain locally accessible operations. An attacker with low-level privileges on the system can bypass these authorization checks to execute code with the privileges of the Windows Admin Center process. The attack vector is local, requires low privileges, no user interaction, and has low attack complexity, making it straightforward for any authenticated local user to attempt. No public technical write-up or proof-of-concept code has been identified at this time (Microsoft MSRC, Feedly).
Successful exploitation grants an attacker high impact across confidentiality, integrity, and availability — effectively achieving full compromise of the Windows Admin Center process and the data it can access. Because Windows Admin Center is a server management tool with broad administrative capabilities, privilege escalation through this vulnerability could expose sensitive system configurations, credentials, and managed server data. The CISA SSVC assessment notes the technical impact as "total," reflecting the potential for complete system control within the scope of the affected application (Feedly).
cmd.exe, powershell.exe) initiated by non-administrative user sessions.Microsoft released a patch on July 14, 2026; administrators should upgrade Windows Admin Center to version 2.7.4 (build 2606) or later to remediate this vulnerability. As a compensating control, restrict local access to systems running Windows Admin Center to only trusted, authorized users, minimizing the pool of potential attackers. Organizations should also review and enforce least-privilege principles for all accounts on systems hosting Windows Admin Center (Microsoft MSRC, Feedly).
CVE-2026-58631 was covered as part of broader reporting on Microsoft's July 2026 Patch Tuesday, which addressed a record 570 vulnerabilities including three zero-days. Security outlets including Cybersecurity News, GBHackers, Qualys, and Cisco Talos covered the July 2026 update cycle, though specific commentary on this individual CVE was limited given the large volume of patches released simultaneously (Cybersecurity News, Qualys Blog, Talos Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."