A critical vulnerability (CVE-2026-47301) affecting Microsoft Configuration Manager (SCCM) allows an authenticated domain user to achieve SYSTEM-level code execution. The flaw, rated important with a CVSS score of 8.8, can be exploited via the AdminService REST API where a chunked-upload endpoint does not validate permissions. Microsoft has issued patches in builds 5.0.9135.1031, 5.0.9141.1030, and 5.0.9146.1021. Users are advised to update promptly as the vulnerability poses significant risks, allowing complete control over managed endpoints.
Critical SCCM flaw lets users hijack systems via AdminService API
CyberSIXT Evidence Panel
Article by CyberSIXT