CVE-2026-58631
Windows Admin Center vulnerability analysis and mitigation

Overview

CVE-2026-58631 is an improper authorization vulnerability in Microsoft Windows Admin Center that allows a locally authenticated, low-privileged attacker to execute arbitrary code on the affected system. It was published on July 14, 2026, as part of Microsoft's July 2026 Patch Tuesday release. Affected versions span from 1809.0 up to (but not including) version 2.7.4 (also referenced as build 2606). The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).

Technical details

The root cause is classified as CWE-285 (Improper Authorization), meaning Windows Admin Center fails to properly enforce authorization controls for certain locally accessible operations. An attacker with low-level privileges on the system can bypass these authorization checks to execute code with the privileges of the Windows Admin Center process. The attack vector is local, requires low privileges, no user interaction, and has low attack complexity, making it straightforward for any authenticated local user to attempt. No public technical write-up or proof-of-concept code has been identified at this time (Microsoft MSRC, Feedly).

Impact

Successful exploitation grants an attacker high impact across confidentiality, integrity, and availability — effectively achieving full compromise of the Windows Admin Center process and the data it can access. Because Windows Admin Center is a server management tool with broad administrative capabilities, privilege escalation through this vulnerability could expose sensitive system configurations, credentials, and managed server data. The CISA SSVC assessment notes the technical impact as "total," reflecting the potential for complete system control within the scope of the affected application (Feedly).

Exploitation steps

  1. Gain Local Access: Obtain a low-privileged local user account on a system running a vulnerable version of Windows Admin Center (versions 1809.0 through less than 2.7.4/build 2606).
  2. Identify Windows Admin Center Instance: Confirm that Windows Admin Center is installed and running locally, typically accessible via a browser on a configured port (default: 6516 or 443).
  3. Probe Authorization Controls: Interact with Windows Admin Center's local interface or API endpoints to identify operations or functions that lack proper authorization enforcement (CWE-285).
  4. Bypass Authorization: Craft requests or invoke functionality that the application fails to properly gate behind privilege checks, exploiting the improper authorization flaw.
  5. Execute Arbitrary Code: Leverage the bypassed authorization to execute code in the context of the Windows Admin Center process, which may carry elevated privileges, enabling further system compromise or lateral movement to managed servers.

Indicators of compromise

  • Logs: Unexpected or anomalous entries in Windows Admin Center application logs showing low-privileged user accounts accessing administrative functions or API endpoints not normally accessible to them.
  • Process: Unusual child processes spawned by the Windows Admin Center service process (e.g., cmd.exe, powershell.exe) initiated by non-administrative user sessions.
  • Network: Unexpected outbound connections from the Windows Admin Center host to external IPs, potentially indicating post-exploitation activity such as data exfiltration or C2 communication.
  • File System: New or modified files in the Windows Admin Center installation directory created by non-administrative accounts; unexpected scripts or executables placed in system directories.

Mitigation and workarounds

Microsoft released a patch on July 14, 2026; administrators should upgrade Windows Admin Center to version 2.7.4 (build 2606) or later to remediate this vulnerability. As a compensating control, restrict local access to systems running Windows Admin Center to only trusted, authorized users, minimizing the pool of potential attackers. Organizations should also review and enforce least-privilege principles for all accounts on systems hosting Windows Admin Center (Microsoft MSRC, Feedly).

Community reactions

CVE-2026-58631 was covered as part of broader reporting on Microsoft's July 2026 Patch Tuesday, which addressed a record 570 vulnerabilities including three zero-days. Security outlets including Cybersecurity News, GBHackers, Qualys, and Cisco Talos covered the July 2026 update cycle, though specific commentary on this individual CVE was limited given the large volume of patches released simultaneously (Cybersecurity News, Qualys Blog, Talos Blog).

Additional resources


SourceThis report was generated using AI

Related Windows Admin Center vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56197HIGH8.8
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 14, 2026
CVE-2026-56196HIGH8.8
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 14, 2026
CVE-2026-58631HIGH7.8
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 14, 2026
CVE-2026-56171HIGH7.5
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 17, 2026
CVE-2026-58643MEDIUM6.1
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management