CVE-2026-47301

Published Jul 14, 2026

Last updated 2 months ago

CVSS high 8.8
Microsoft Configuration Manager

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-47301 is an improper access control vulnerability found in Microsoft Configuration Manager (SCCM), specifically within the AdminService REST API. This flaw stems from a missing role-based access control (RBAC) check, which allows an authenticated domain user to submit a malicious CAB archive without possessing the necessary SCCM administrative roles. This vulnerability is a component of a larger, multi-step remote code execution (RCE) attack chain. While Microsoft has released a patch addressing CVE-2026-47301, other elements of the complete RCE chain, such as path traversal and weak code-signing validation, are expected to be fully resolved in later updates.

Description
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
configuration_manager_2503, configuration_manager_2509, configuration_manager_2603

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-284

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.