logo

Azure Identity Token Vulnerability Enables Tenant-Wide Compromise in Windows Admin Center

ID: f01918ba-2e59-5c27-812b-24aa3100206a

STIX ID: report--f01918ba-2e59-5c27-812b-24aa3100206a

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-15

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A high-severity flaw (CVE-2026-20965) in Windows Admin Center's Azure Single Sign-On allows attackers with local admin on a WAC-enabled VM/Arc machine and a privileged Azure Portal connection to mix tokens (stolen WAC.CheckAccess + forged PoP) to perform tenant-wide RCE, lateral movement, and cross-subscription compromise; Microsoft patched it in Windows Admin Center Azure Extension v0.70.00 on 2026-01-13 and operators should apply the update, restrict JIT/NSG to gateway-only, and monitor for anomalous WAC accounts and InvokeCommand activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.