CVE-2026-50523

Summary

Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.

Affected Software

VendorProductVersion RangeStatus
MicrosoftPowerShell 7.47.4.0 < 7.4.19.0affected
MicrosoftPowerShell 7.57.5.0 < 7.5.10.0affected
MicrosoftPowerShell 7.67.6.0 < 7.6.5affected

Weaknesses

  • CWE-77: CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')

References