
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-58643 is a Cross-Site Scripting (XSS) vulnerability in Microsoft Windows Admin Center that allows an unauthenticated network attacker to perform spoofing attacks. The vulnerability stems from improper neutralization of input during web page generation (CWE-79) and affects Windows Admin Center versions from 1809.0 up to (but not including) version 2511. It was disclosed on July 16, 2026, as part of Microsoft's security update guidance, with a CVSS v3.1 base score of 6.1 (Medium) (Microsoft MSRC, GitHub Advisory).
The root cause is improper neutralization of user-controllable input before it is rendered in web pages served to other users (CWE-79), a classic XSS weakness. An unauthenticated attacker can inject malicious scripts into Windows Admin Center web pages over the network; however, exploitation requires user interaction — a victim must visit or interact with a crafted or compromised page. The changed scope (S:C) in the CVSS vector indicates that the impact extends beyond the vulnerable component itself, potentially affecting the user's browser session and any resources accessible within it (Microsoft MSRC, GitHub Advisory).
Successful exploitation allows an attacker to inject and execute malicious scripts in the context of a victim's browser session within Windows Admin Center, resulting in low confidentiality and low integrity impact with no availability impact. The primary risk is spoofing — attackers can deceive administrators into performing unintended actions, steal session tokens or credentials, or exfiltrate limited data accessible within the admin interface. Because Windows Admin Center is a privileged server management tool, XSS exploitation could potentially be leveraged to pivot to managed servers or escalate privileges if an administrator's session is hijacked (Microsoft MSRC, GitHub Advisory).
Microsoft has released a patch addressing this vulnerability; organizations should update Windows Admin Center to version 2511 or later immediately (Microsoft MSRC). As interim mitigations, restrict access to Windows Admin Center to trusted internal networks and authenticated users only, and implement Content Security Policy (CSP) headers to limit script execution. Additionally, educate administrators to be cautious of unsolicited links or requests to interact with the admin console, and monitor audit logs for anomalous administrative actions.
A post on Infosec.exchange (Mastodon) by security researcher @wdormann referenced the vulnerability shortly after disclosure, indicating some community awareness (Infosec.exchange). No major vendor statements beyond the Microsoft MSRC advisory or significant media coverage have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."