CVE-2026-56196
Analyzed Analyzed - Analysis Complete

Windows Admin Center Relative Path Traversal Vulnerability

Vulnerability report for CVE-2026-56196, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-24

Assigner: Microsoft Corporation

Description

Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-24
Generated
2026-08-03
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
microsoft windows_admin_center to 2606 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-23 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-56196 is a relative path traversal vulnerability in Windows Admin Center. This flaw allows an authorized attacker to traverse directories and access files or directories outside the intended restricted path.

Due to this vulnerability, the attacker can execute arbitrary code over a network, meaning they can run malicious commands or software on the affected system remotely.

The vulnerability requires the attacker to be authorized, indicating they must have some level of access or privileges within the system or network.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the relative path traversal vulnerability in Windows Admin Center (CVE-2026-56196). Detection typically involves checking for unusual network traffic or unauthorized access attempts to the Windows Admin Center service, but no technical details or commands are available in the given resources.

You may refer to Microsoft's official guidance or security tools (e.g., Microsoft Defender for Endpoint, network monitoring solutions) to scan for signs of exploitation or misconfigurations related to this vulnerability.

Impact Analysis

This vulnerability can have severe impacts if exploited, including:

  • Remote Code Execution (RCE): An attacker can execute arbitrary code on the affected system, potentially taking full control of it.
  • Data Breach: Sensitive data stored on the system could be accessed, stolen, or manipulated by the attacker.
  • System Compromise: The attacker could install malware, create backdoors, or disrupt system operations, leading to downtime or further attacks.
  • Lateral Movement: Once inside the network, the attacker could move to other systems, escalating the scope of the attack.
Compliance Impact

This vulnerability can impact compliance with several standards and regulations, depending on the data and systems involved:

  • GDPR (General Data Protection Regulation): If the affected system processes or stores personal data of EU citizens, a breach could lead to unauthorized access or disclosure of this data. This may result in non-compliance with GDPR requirements for data protection and breach notification, potentially leading to fines or legal action.
  • HIPAA (Health Insurance Portability and Accountability Act): If the system handles protected health information (PHI), exploitation of this vulnerability could lead to unauthorized access or disclosure of PHI. This would violate HIPAA's Privacy and Security Rules, resulting in penalties and mandatory corrective actions.
  • Other Standards: Compliance with frameworks like ISO 27001, NIST, or PCI DSS may also be affected if the vulnerability leads to unauthorized access, data breaches, or failure to maintain secure systems. Organizations may need to report the incident and take remediation steps to avoid non-compliance.
Mitigation Strategies

Based on the provided context, the following steps are recommended to mitigate the vulnerability:

  • Apply the latest security updates from Microsoft for Windows Admin Center. Refer to the official Microsoft Security Update Guide for patches addressing CVE-2026-56196.
  • Restrict network access to the Windows Admin Center service to trusted users and systems only. Use firewalls or network segmentation to limit exposure.
  • Monitor for suspicious activity or unauthorized access attempts targeting the Windows Admin Center service.
  • Review and enforce least-privilege access controls for users interacting with Windows Admin Center to reduce the risk of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56196. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart