CVE-2026-58643
Windows Admin Center vulnerability analysis and mitigation

Overview

CVE-2026-58643 is a Cross-Site Scripting (XSS) vulnerability in Microsoft Windows Admin Center that allows an unauthenticated network attacker to perform spoofing attacks. The vulnerability stems from improper neutralization of input during web page generation (CWE-79) and affects Windows Admin Center versions from 1809.0 up to (but not including) version 2511. It was disclosed on July 16, 2026, as part of Microsoft's security update guidance, with a CVSS v3.1 base score of 6.1 (Medium) (Microsoft MSRC, GitHub Advisory).

Technical details

The root cause is improper neutralization of user-controllable input before it is rendered in web pages served to other users (CWE-79), a classic XSS weakness. An unauthenticated attacker can inject malicious scripts into Windows Admin Center web pages over the network; however, exploitation requires user interaction — a victim must visit or interact with a crafted or compromised page. The changed scope (S:C) in the CVSS vector indicates that the impact extends beyond the vulnerable component itself, potentially affecting the user's browser session and any resources accessible within it (Microsoft MSRC, GitHub Advisory).

Impact

Successful exploitation allows an attacker to inject and execute malicious scripts in the context of a victim's browser session within Windows Admin Center, resulting in low confidentiality and low integrity impact with no availability impact. The primary risk is spoofing — attackers can deceive administrators into performing unintended actions, steal session tokens or credentials, or exfiltrate limited data accessible within the admin interface. Because Windows Admin Center is a privileged server management tool, XSS exploitation could potentially be leveraged to pivot to managed servers or escalate privileges if an administrator's session is hijacked (Microsoft MSRC, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible Windows Admin Center instances running versions between 1809.0 and below 2511 using network scanning tools or Shodan.
  2. Craft malicious payload: Construct an XSS payload designed to execute in the context of the Windows Admin Center web interface (e.g., a script that exfiltrates cookies or session tokens, or performs actions on behalf of the authenticated administrator).
  3. Deliver payload: Inject the malicious script via a vulnerable input field or parameter within Windows Admin Center that is not properly sanitized before being rendered in the web page.
  4. Social engineering: Trick an authenticated administrator into visiting a crafted URL or interacting with the injected content (e.g., via phishing email or malicious link).
  5. Achieve objective: Once the victim's browser executes the injected script, the attacker can steal session cookies, perform spoofing, capture credentials, or issue administrative commands through the compromised session (Microsoft MSRC, GitHub Advisory).

Indicators of compromise

  • Network: Unusual outbound HTTP/HTTPS requests from administrator browsers to unknown external hosts originating from Windows Admin Center sessions; unexpected data exfiltration patterns from the admin console.
  • Logs: Windows Admin Center access logs showing requests with encoded or suspicious script content in URL parameters or POST body fields; unexpected API calls or administrative actions in audit logs not correlated with known administrator activity.
  • Browser/Session: Unexpected session token usage from unfamiliar IP addresses or geographic locations; duplicate or replayed session tokens in authentication logs.
  • Process: Unexpected child processes or scripts spawned in the context of the Windows Admin Center service following administrator interaction with the interface.

Mitigation and workarounds

Microsoft has released a patch addressing this vulnerability; organizations should update Windows Admin Center to version 2511 or later immediately (Microsoft MSRC). As interim mitigations, restrict access to Windows Admin Center to trusted internal networks and authenticated users only, and implement Content Security Policy (CSP) headers to limit script execution. Additionally, educate administrators to be cautious of unsolicited links or requests to interact with the admin console, and monitor audit logs for anomalous administrative actions.

Community reactions

A post on Infosec.exchange (Mastodon) by security researcher @wdormann referenced the vulnerability shortly after disclosure, indicating some community awareness (Infosec.exchange). No major vendor statements beyond the Microsoft MSRC advisory or significant media coverage have been identified at this time.

Additional resources


SourceThis report was generated using AI

Related Windows Admin Center vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56197HIGH8.8
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 14, 2026
CVE-2026-56196HIGH8.8
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 14, 2026
CVE-2026-58631HIGH7.8
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 14, 2026
CVE-2026-56171HIGH7.5
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 17, 2026
CVE-2026-58643MEDIUM6.1
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management