CVE-2026-56185

Summary

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

Affected Software

VendorProductVersion RangeStatus
MicrosoftWindows Admin Center1809.0 < 2.6.5.16affected

Weaknesses

  • CWE-287: CWE-287: Improper Authentication
  • CWE-94: CWE-94: Improper Control of Generation of Code ('Code Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References