CVE-2026-47301 is an improper access-control vulnerability in Microsoft Configuration Manager. The vulnerable AdminService chunked-upload endpoint failed to enforce the role-based authorization applied by a related upload endpoint, allowing an authenticated domain user to submit a crafted console-extension archive without the intended Configuration Manager permissions. In the reported exploit chain, insufficient archive signature validation and path traversal during archive extraction enable writes outside the intended extraction directory. An attacker can then replace a secondary library loaded by the SMS Executive service; because that service runs as NT AUTHORITY\SYSTEM, the resulting code executes with SYSTEM privileges on a Configuration Manager primary site server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a complete proof-of-concept exploit chain for CVE-2026-47301 against Microsoft Configuration Manager (SCCM). It is not tied to a common exploit framework. The repo has two main components: (1) a .NET 8 C# uploader client (C1_UploadExtensionInChunks_AFW.cs) that talks to SCCM AdminService endpoints to upload a malicious CAB, and (2) a C++ proxy DLL project (AdSource_Proxy/) that produces a malicious adsource.dll while forwarding 147 exports to a renamed legitimate adsource_original.dll to avoid crashing the service. The C# tool supports two chains: default C1 using UploadExtensionInChunks, described as lacking RBAC enforcement, and optional C2 using UploadExtension with RBAC requirements. It builds URLs from a supplied host and optional scheme/port, and exposes probe/write modes for testing and uploading payloads. The XML role file documents the minimum permission needed for the RBAC-checked path. The CAB-building artifact (cabslip.ddf) shows the path traversal primitive explicitly via '..\\..\\..\\..\\', packaging adsource.dll and adsource_original.dll so extraction escapes the intended directory and lands in the SCCM bin\\X64 path. The README explains this is used to hijack DLL loading in the SCCM service chain. The C++ DLL payload is operational and clearly malicious: DllMain launches a worker thread on load, which dynamically loads netapi32.dll and uses NetUser* APIs to locate the built-in RID 500 Administrator account by SID, log its original name, rename it to 'omrispy', enable/unlock it, set non-expiring password flags, and assign the hardcoded password 'Xm#Poc-2026!Adm1n$Ok'. It logs execution details to C:\POC.txt. Build.ps1 and New-DllForwarderPragmas.ps1 automate creation of a forwarder DLL so the malicious DLL preserves original exports and remains stable in the target process. Overall, this repository is a real exploit PoC with a working payload, combining web-accessible upload abuse, CAB path traversal arbitrary file write, and local DLL hijacking to obtain SYSTEM-level execution on a Windows SCCM site server.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown
A Microsoft Configuration Manager (SCCM) SMS Executive service vulnerability/exploit chain involving placement of a malicious adsource.dll in the SCCMProvider bin\X64 directory. Successful exploitation yields code execution in the SCCM service context and can spawn a SYSTEM-level process under smsexec.exe.
A DLL side-loading vulnerability affecting the SCCM SMS Provider, with adsource.dll staged in its bin\X64 directory as part of the described exploitation simulation.
A DLL side-loading/planting vulnerability in the Microsoft Configuration Manager (SCCM) SMS Provider component. An attacker able to place a malicious adsource.dll in the SCCMProvider bin\X64 path can cause the SMS Provider service to load it, potentially resulting in SYSTEM-level code execution on hosts running the SMS Provider role.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.