Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-73004

CVE-2026-73004: Windows Autopilot Auth Bypass Vulnerability

CVE-2026-73004 is an authentication bypass flaw in Windows Autopilot that enables authorized attackers to tamper with critical functions locally. This article covers technical details, affected versions, and mitigation strategies.

Updated:

CVE-2026-73004 Overview

CVE-2026-73004 is a missing authentication vulnerability in Windows Autopilot, Microsoft's device provisioning service. The flaw allows an authorized local attacker to tamper with integrity-sensitive functionality that lacks proper authentication controls. Microsoft published the advisory on September 8, 2026, and classified the weakness under [CWE-306] Missing Authentication for Critical Function. Exploitation requires local access and low privileges but no user interaction. The impact is limited to integrity, with no confidentiality or availability consequences reported.

Critical Impact

An authenticated local user can tamper with Windows Autopilot operations because a critical function does not enforce authentication, potentially altering device provisioning state or configuration integrity.

Affected Products

  • Windows Autopilot (Microsoft device provisioning service)
  • Refer to the Microsoft Security Update CVE-2026-73004 advisory for the current list of impacted builds
  • Windows client editions that consume Autopilot provisioning workflows

Discovery Timeline

  • 2026-09-08 - CVE-2026-73004 published to NVD
  • 2026-09-10 - Last updated in NVD database

Technical Details for CVE-2026-73004

Vulnerability Analysis

The vulnerability resides in a Windows Autopilot code path that performs a security-relevant operation without validating the caller's identity. Because the function is exposed to local principals, an authorized user with low privileges can invoke it and alter data or configuration that should be restricted to a higher-trust component. The result is an integrity-only impact: the attacker can modify state, but cannot read protected data or crash the service through this issue alone. Windows Autopilot governs enrollment and configuration of managed devices, so tampering with its functions can affect downstream provisioning outcomes.

Root Cause

The root cause is classified as [CWE-306] Missing Authentication for Critical Function. A code path performs an action that changes system or provisioning state without first verifying that the caller is authorized to request it. The design assumes trust based on locality or process context rather than on an explicit authentication check.

Attack Vector

Exploitation requires local access to an affected system and an authenticated session with low privileges. No user interaction is required. An attacker with a standard account can reach the vulnerable Autopilot function and issue a tampering request that the service accepts without an authentication check. See the Microsoft Security Update CVE-2026-73004 advisory for vendor technical detail.

No verified proof-of-concept code is publicly available. The vulnerability mechanism is described in prose per the advisory; refer to the Microsoft Security Response Center for authoritative technical information.

Detection Methods for CVE-2026-73004

Indicators of Compromise

  • Unexpected modifications to Windows Autopilot provisioning profiles or device configuration state on managed endpoints
  • Autopilot-related service invocations originating from standard user contexts rather than SYSTEM or management processes
  • Anomalous local API calls or IPC messages targeting Autopilot components outside normal enrollment windows

Detection Strategies

  • Baseline legitimate Autopilot activity and alert on deviations initiated by non-administrative local principals
  • Correlate endpoint process telemetry with Autopilot configuration changes to identify unauthorized tampering attempts
  • Review Windows event logs and Autopilot diagnostic traces for state changes that lack a corresponding management action

Monitoring Recommendations

  • Enable verbose logging for Windows Autopilot and forward events to a centralized analytics platform
  • Monitor for privilege-boundary crossings where standard user processes trigger provisioning state changes
  • Track integrity of Autopilot registry keys, scheduled tasks, and configuration files with file integrity monitoring

How to Mitigate CVE-2026-73004

Immediate Actions Required

  • Apply the Microsoft security update referenced in the Microsoft Security Update CVE-2026-73004 advisory as soon as it is available in your patch cycle
  • Inventory endpoints that participate in Autopilot enrollment and prioritize patching for shared or kiosk devices where multiple local users have access
  • Restrict interactive local logon on Autopilot-managed devices to trusted administrative accounts where operationally feasible

Patch Information

Microsoft has published the security update guidance for CVE-2026-73004. Consult the Microsoft Security Update CVE-2026-73004 advisory for the authoritative list of affected builds, KB article numbers, and download links. Apply updates through Windows Update, Windows Server Update Services (WSUS), or Microsoft Intune according to your standard change management process.

Workarounds

  • No official vendor workaround is published; patching is the recommended remediation path
  • Limit the number of standard user accounts with local logon rights on Autopilot-enrolled devices to reduce the exposure window
  • Enforce least privilege and application control policies to constrain what local users can execute on affected systems

Refer to the vendor advisory for any configuration guidance released after patch availability.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.