CVE-2026-26119
HighPublished
Windows Admin Center Elevation of Privilege Vulnerability
- Published
- Feb 17, 2026
- Updated
- Aug 19, 2026
- Assigning CNA
- microsoft
- Evidence observed
- Aug 10, 2026
Primary CVSS
8.8/ 10High
Windows Admin Center Elevation of Privilege Vulnerability
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HLow · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
WAC RCE - CVE-2026-26119 Windows Admin Center authenticated RCE via WinREST/PowerShell invokeCommand.
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.