Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
PoC: CVE-2026-26119
WAC RCE - CVE-2026-26119 Windows Admin Center authenticated RCE via WinREST/PowerShell invokeCommand.
PoC: CVE-2026-26119
WAC RCE - CVE-2026-26119 Windows Admin Center authenticated RCE via WinREST/PowerShell invokeCommand.
PoC: WACJack
Research codebase for reproducing and measuring the CVE-2026-26119 Windows Admin Center auth-reflection chain in lab environments.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free