Critical Windows Admin Center Vulnerability Allows Privilege Escalation
## Cybersecurity: Windows Admin Center Vulnerability Update
Cybersecurity: Windows Admin Center Vulnerability Update
A critical security update has been released to address a high-severity elevation of privilege vulnerability in Windows Admin Center (WAC), identified as CVE-2026-26119.
The vulnerability is rated CVSS 8.8 (Critical) and results from improper authentication (CWE-287), potentially enabling an authorized attacker to gain elevated network privileges. This issue affects Windows Admin Center version 2.6.4 and was publicly disclosed on Tue, Feb 17, 2026.
The flaw allows attackers with limited privileges on the system to escalate their access without further user interaction. Although there is no active exploitation reported, Microsoft warns that exploitation is "more likely" due to low attack complexity and network exposure of WAC deployments. Successful exploitation grants attackers the same privileges as the user running the affected application.
As Windows Admin Center is frequently used for centralized system administration, privilege escalation could lead to full control of managed servers, system settings modification, and access to sensitive data.
This issue affects Windows Admin Center version 2.6.4 and was publicly disclosed on Tue, Feb 17, 2026.
Microsoft credits Andrea Pierini from Semperis for responsibly reporting the vulnerability. The company has released an official fix through the latest Windows Admin Center security update and strongly advises administrators to apply the patch immediately. Users can access the update and release notes through Microsoft’s official channels .
No proof-of-concept (PoC) code has been published yet, but the exploitability index indicates a higher likelihood of exploit development in the near term. Given WAC's exposure across enterprise environments, delaying patch deployment could leave networks vulnerable to lateral movement and privilege misuse attacks.
Administrators are urged to follow Microsoft’s security update guidance, review account permissions, and monitor event logs for unusual privilege escalations. More details on the official CVE can be found via CVE.org and Microsoft’s Security Update Guide.
Based on reporting by Cyber Security News.
