CVE-2026-26119 PoC: Windows Admin Center authenticated RCE
github.com | tool | CVE-2026-26119 | #rce | #public-poc | #privilege-escalation | #windows-security | #windows-admin-center | #powershell | #exploit | #poc | #reverse-shell | #cve-2026-26119
Summary
A PoC for CVE-2026-26119, an authenticated remote code execution vulnerability in Windows Admin Center, exploiting the WinREST/PowerShell invokeCommand path with steps to obtain a reverse shell.
Why it matters
The PoC shows that a low-privileged valid account can turn the flaw into remote command execution over the network. Upgrade to Windows Admin Center 2.6.4 or later and review WAC accounts and anomalous PowerShell activity.
- Vendor
- Microsoft
- Product
- Windows Admin Center
- Affected versions
- < 2.6.4
- CVSS
- 8.8
- Published
- Collected
Skip to content