Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-26143

Опубликовано: 14 апр. 2026
Источник: msrc
CVSS3: 7.8
EPSS Низкий

Описание

Microsoft PowerShell Security Feature Bypass Vulnerability

Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

FAQ

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?

An attacker would have to send the victim a malicious file that the victim would have to execute.

What kind of security feature could be bypassed by successfully exploiting this vulnerability?

Exploiting this vulnerability bypasses dynamic-expression security checks which may lead to arbitrary code execution when then -SkipLimitCheck is used with Import-PowerShellDataFile. If you do not use the -SkipLimitCheck switch, you are not affected.

Is the Windows native version of PowerShell affected by this vulnerability?

No, this vulnerability was introduced after PowerShell was forked from Windows powerShell so the inbox version is not affected.

The current store app addresses the vulnerability.

Обновления

ПродуктСтатьяОбновление
PowerShell 7.4
PowerShell 7.5

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

EPSS

Процентиль: 41%
0.00536
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
4 месяца назад

Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

CVSS3: 7.8
github
4 месяца назад

Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

CVSS3: 7.8
fstec
4 месяца назад

Уязвимость интерпретатора команд PowerShell операционной системы Windows, позволяющая нарушителю обойти существующие ограничения безопасности

CVSS3: 7.8
redos
22 дня назад

Уязвимость powershell

EPSS

Процентиль: 41%
0.00536
Низкий

7.8 High

CVSS3