Command Injection Vulnerability in Microsoft PowerShell
CVE-2026-50523
7.8HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 14 August 2026
What is CVE-2026-50523?
An improper neutralization of special elements enables an authorized attacker to perform command injection in Microsoft PowerShell. This vulnerability allows execution of arbitrary code locally, potentially compromising system integrity. Users are encouraged to apply security updates to mitigate any risk associated with this vulnerability. For additional information and guidance, consult the official Microsoft Advisory.
Affected Version(s)
PowerShell 7.4 7.4.0 < 7.4.19.0
PowerShell 7.5 7.5.0 < 7.5.10.0
PowerShell 7.6 7.6.0 < 7.6.5