DIRAS TAKE
Urgent: public exploit code exists, so prioritize updating to the vendor fixed builds listed for your branch; restrict access to Configuration Manager while you patch.
What is CVE-2026-47301?
A low-privilege, authorized user with network access can elevate privileges on Microsoft Configuration Manager, enabling broader administrative control. CVE-2026-47301 affects Microsoft Configuration Manager 5.x releases before fixed builds; affected ranges include 1.0.0 through before 5.0.9135.1031 (fixed in 5.0.9135.1031), 1.0.0 through before 5.0.9141.1030 (fixed in 5.0.9141.1030), and 1.0.0 through before 5.0.9146.1021 (fixed in 5.0.9146.1021). An attacker needs network access and an authorized (low-privilege) account to exploit this flaw.
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Microsoft Configuration Manager are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Microsoft Configuration Manager 5.x | 1.0.0 – before 5.0.9135.1031 | 5.0.9135.1031 |
| Microsoft Configuration Manager 2509 5.x | 1.0.0 – before 5.0.9141.1030 | 5.0.9141.1030 |
| Microsoft Configuration Manager 2603 5.x | 1.0.0 – before 5.0.9146.1021 | 5.0.9146.1021 |
Is CVE-2026-47301 being exploited?
Public exploit code is available.
How to fix CVE-2026-47301
- Apply the vendor updates to the fixed builds: 5.0.9135.1031, 5.0.9141.1030 or 5.0.9146.1021 depending on your branch.
- Restrict network exposure of Configuration Manager services and limit administrative access until patches are applied.
- Review and tighten account privileges to remove unnecessary rights from non-admin users.
- Monitor Configuration Manager logs and authentication events for unusual privilege escalation activity.
Frequently asked questions
Is CVE-2026-47301 being actively exploited?
Public exploit code for CVE-2026-47301 is available; there is no CISA KEV listing for this CVE as of the provided date.
Which Microsoft Configuration Manager versions are affected by CVE-2026-47301?
Affected ranges include 1.0.0 through before 5.0.9135.1031 (fixed in 5.0.9135.1031), 1.0.0 through before 5.0.9141.1030 (fixed in 5.0.9141.1030), and 1.0.0 through before 5.0.9146.1021 (fixed in 5.0.9146.1021).
Is there a patch for CVE-2026-47301?
Yes. Microsoft published fixed builds: 5.0.9135.1031, 5.0.9141.1030 or 5.0.9146.1021 depending on your branch.
Does CVE-2026-47301 require authentication?
Yes. The vulnerability requires an authorized (low-privilege) account and network access to the Microsoft Configuration Manager service.
References
- nvd.nist.gov/vuln/detail/CVE-2026-47301
- cve.org/CVERecord?id=CVE-2026-47301
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47301
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026