CVE-2026-62873
Published Aug 7, 2026Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
21 CVEs tagged to microsoft / windows_admin_center — 2 Critical, 14 High, 5 Medium, 0 Low, 0 Unrated.
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.
Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally.
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally.
External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally.
Windows Admin Center Spoofing Vulnerability
Windows Admin Center Security Feature Bypass Vulnerability
An elevation of privilege vulnerability exists when Windows Admin Center improperly impersonates operations in certain situations, aka 'Windows Admin Center Elevation of Privilege…