Junglewise Threat Intelligence

CVE-2026-50523: Microsoft PowerShell command injection

CVE-2026-50523 · Severity: high · CVSS 7.8 · Published 2026-08-14

Technologies: Microsoft PowerShell. Vendors: Microsoft.

Executive brief

Microsoft PowerShell, a widely-used command-line automation tool in Windows environments, contains a command injection vulnerability. An authorized attacker with local access could exploit this flaw to execute arbitrary code on affected systems, potentially compromising system integrity and data security.

Technical details

The vulnerability is an improper neutralization of special elements in command processing (command injection, CWE-77/78) within Microsoft PowerShell. The flaw allows an authorized attacker with local access to execute arbitrary code by injecting specially-crafted commands. Attack requires local access and attacker authorization. No patch availability information is provided in the advisory.

Affected products

  • Microsoft PowerShell

Timeline

  • 2026-08-14: disclosed

References

Related threats