securityonline.info 8/20/2026, 2:07:48 PM · external

Critical SCCM flaw lets users hijack systems via AdminService API

Critical SCCM flaw lets users hijack systems via AdminService API
CyberSIXT Evidence Panel
Primary Source msrc.microsoft.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

A critical vulnerability (CVE-2026-47301) affecting Microsoft Configuration Manager (SCCM) allows an authenticated domain user to achieve SYSTEM-level code execution. The flaw, rated important with a CVSS score of 8.8, can be exploited via the AdminService REST API where a chunked-upload endpoint does not validate permissions. Microsoft has issued patches in builds 5.0.9135.1031, 5.0.9141.1030, and 5.0.9146.1021. Users are advised to update promptly as the vulnerability poses significant risks, allowing complete control over managed endpoints.

View Primary Source Via securityonline.info

Article by CyberSIXT