CVE-2026-20967
Published: 10 March 2026
Description
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Security Summary
CVE-2026-20967 is an improper input validation vulnerability (CWE-20) affecting Microsoft System Center Operations Manager. Published on 2026-03-10T18:18:05.987, it carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating high severity due to its potential for significant impact.
An attacker with low privileges (PR:L) can exploit this vulnerability over the network (AV:N) with low attack complexity and no user interaction required. Successful exploitation allows privilege escalation, granting high-impact access to confidentiality, integrity, and availability of the affected system.
The Microsoft Security Response Center advisory provides details on mitigation and patches at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20967.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
The vulnerability enables privilege escalation from low privileges (PR:L) over the network (AV:N) with no user interaction, directly facilitating T1068: Exploitation for Privilege Escalation.