CVE-2026-23660

7.8

Microsoft · Windows Admin Center in Azure Portal

An improper access control vulnerability in Azure Portal Windows Admin Center enables an authenticated local attacker to escalate their privileges.

Executive summary

A high-severity privilege escalation vulnerability in Microsoft Windows Admin Center within the Azure Portal allows authorized users to elevate their local permissions.

Vulnerability

The flaw stems from improper access control (CWE-284) that allows an attacker with low-level local privileges to perform unauthorized actions. The vulnerability is triggered locally, requiring the attacker to already possess a baseline level of authenticated access to the system.

Business impact

Successful exploitation of this vulnerability permits a local user to escalate their privileges, potentially gaining full administrative control over the affected system. This compromise threatens the integrity and confidentiality of the host environment, risking total system takeover. With a CVSS score of 7.8, this vulnerability represents a significant security risk that warrants prompt remediation to prevent lateral movement or further unauthorized activity.

Remediation

Immediate Action: Update Microsoft Windows Admin Center in the Azure Portal to version 2.6.4 or later immediately.

Proactive Monitoring: Review local system access logs for anomalous privilege escalation events or unauthorized modifications to administrative accounts.

Compensating Controls: Ensure that the principle of least privilege is strictly enforced for all local users to limit the potential impact of a local privilege escalation attempt.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit available.

Analyst recommendation

The risk posed by local privilege escalation is significant, particularly in shared or multi-user environments where a compromised low-privilege account could lead to a full system breach. Administrators must prioritize the deployment of the vendor-supplied update to version 2.6.4 to eliminate this vulnerability. Until updates can be applied, ensure that access to the affected management interface is restricted to authorized personnel only.

More Microsoft CVEs

Sources