• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-47301: authenticated privilege escalation in Microsoft Microsoft Configuration Manager

A low-privilege, authorized user with network access can elevate privileges on Microsoft Configuration Manager, enabling broader administrative control. CVE-2026-47301 affects Microsoft Configuration Manager 5.x releases before fixed builds; affected ranges include 1.0.0 through before 5.0.9135.1031 (fixed in 5.0.9135.1031), 1.0.0 through before 5.0.9141.1030 (fixed in 5.0.9141.1030), and 1.0.0 through before 5.0.9146.1021 (fixed in 5.0.9146.1021). An attacker needs network access and an authorized (low-privilege) account to exploit this flaw.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
8.8HIGH
EPSS
0.00778
CWE
CWE-284
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists, so prioritize updating to the vendor fixed builds listed for your branch; restrict access to Configuration Manager while you patch.

What is CVE-2026-47301?

A low-privilege, authorized user with network access can elevate privileges on Microsoft Configuration Manager, enabling broader administrative control. CVE-2026-47301 affects Microsoft Configuration Manager 5.x releases before fixed builds; affected ranges include 1.0.0 through before 5.0.9135.1031 (fixed in 5.0.9135.1031), 1.0.0 through before 5.0.9141.1030 (fixed in 5.0.9141.1030), and 1.0.0 through before 5.0.9146.1021 (fixed in 5.0.9146.1021). An attacker needs network access and an authorized (low-privilege) account to exploit this flaw.

Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Microsoft Configuration Manager are affected?

BRANCHAFFECTEDFIXED
Microsoft Configuration Manager 5.x1.0.0 – before 5.0.9135.10315.0.9135.1031
Microsoft Configuration Manager 2509 5.x1.0.0 – before 5.0.9141.10305.0.9141.1030
Microsoft Configuration Manager 2603 5.x1.0.0 – before 5.0.9146.10215.0.9146.1021

Is CVE-2026-47301 being exploited?

Public exploit code is available.

How to fix CVE-2026-47301

  1. Apply the vendor updates to the fixed builds: 5.0.9135.1031, 5.0.9141.1030 or 5.0.9146.1021 depending on your branch.
  2. Restrict network exposure of Configuration Manager services and limit administrative access until patches are applied.
  3. Review and tighten account privileges to remove unnecessary rights from non-admin users.
  4. Monitor Configuration Manager logs and authentication events for unusual privilege escalation activity.

Frequently asked questions

Is CVE-2026-47301 being actively exploited?

Public exploit code for CVE-2026-47301 is available; there is no CISA KEV listing for this CVE as of the provided date.

Which Microsoft Configuration Manager versions are affected by CVE-2026-47301?

Affected ranges include 1.0.0 through before 5.0.9135.1031 (fixed in 5.0.9135.1031), 1.0.0 through before 5.0.9141.1030 (fixed in 5.0.9141.1030), and 1.0.0 through before 5.0.9146.1021 (fixed in 5.0.9146.1021).

Is there a patch for CVE-2026-47301?

Yes. Microsoft published fixed builds: 5.0.9135.1031, 5.0.9141.1030 or 5.0.9146.1021 depending on your branch.

Does CVE-2026-47301 require authentication?

Yes. The vulnerability requires an authorized (low-privilege) account and network access to the Microsoft Configuration Manager service.

References