CVE-2026-42834

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:windows_admin_center:*:*:*:*:*:azure:*:*

History

01 Jun 2026, 19:16

Type Values Removed Values Added
Summary (en) Improper link resolution before file access ('link following') in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally. (en) Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

20 May 2026, 18:29

Type Values Removed Values Added
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42834 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42834 - Vendor Advisory
CPE cpe:2.3:a:microsoft:windows_admin_center:*:*:*:*:*:azure:*:*
First Time Microsoft
Microsoft windows Admin Center

20 May 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-20 13:16

Updated : 2026-06-01 19:16


NVD link : CVE-2026-42834

Mitre link : CVE-2026-42834

CVE.ORG link : CVE-2026-42834


JSON object : View

Products Affected

microsoft

  • windows_admin_center
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')