CVE-2026-50502
Analyzed Analyzed - Analysis Complete

Insufficient Access Control in Windows Event Logging Service Allows Remote Code Execution

Vulnerability report for CVE-2026-50502, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 22 associated CPEs
Vendor Product Version / Range
microsoft windows_server_2012 r2
microsoft windows_server_2012 *
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_server_2016 to 10.0.14393.9339 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1220 The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50502 is a vulnerability in the Windows Event Logging Service. It involves insufficient granularity of access control, meaning the service does not properly restrict access permissions at a detailed level.

An authorized attacker with limited privileges can exploit this flaw to execute arbitrary code over a network. This could allow the attacker to gain control over the affected system remotely.

The vulnerability is classified as a remote code execution (RCE) issue with a CVSS base score of 8.0, indicating a high severity level.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the vulnerability in the Windows Event Logging Service. Detection may require checking for unusual access patterns or unauthorized modifications to the service, but no direct guidance is available in the given resources.

To detect potential exploitation, you could monitor network traffic for unexpected connections to the Windows Event Logging Service or review event logs for anomalous activity. However, the exact commands or tools are not specified in the provided text.

Impact Analysis

If exploited, this vulnerability could have several impacts on you or your organization:

  • An attacker could execute malicious code on your system, potentially taking full control of it.
  • Sensitive data stored or processed on the affected system could be accessed, modified, or stolen.
  • The attacker could use the compromised system to launch further attacks within your network.
  • System availability could be disrupted if the attacker executes code that crashes or disables critical services.
Compliance Impact

This vulnerability could impact compliance with several standards and regulations, depending on the context of its exploitation:

  • GDPR: If the vulnerability leads to unauthorized access or disclosure of personal data, it could violate GDPR requirements for data protection and breach notification.
  • HIPAA: For organizations handling protected health information (PHI), exploitation of this vulnerability could result in unauthorized access to PHI, violating HIPAA's security and privacy rules.
  • Other standards like ISO 27001 or NIST frameworks require organizations to maintain secure systems. Failure to patch or mitigate this vulnerability could result in non-compliance with these standards.

Organizations should assess the potential impact of this vulnerability on their compliance posture and take appropriate remediation steps.

Mitigation Strategies

The provided context does not include specific mitigation steps for CVE-2026-50502. However, general best practices for mitigating such vulnerabilities may include:

  • Apply the latest security updates or patches from Microsoft as soon as they are available. Refer to the Microsoft Update Guide for this CVE for official patches.
  • Restrict network access to the Windows Event Logging Service to trusted users and systems only.
  • Review and enforce least-privilege access controls for users and services interacting with the Windows Event Logging Service.
  • Monitor for suspicious activity related to the service, such as unexpected code execution or unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50502. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart