CVE-2026-26143
Received
Received - Intake
Improper Input Validation in Microsoft PowerShell Enables Local Bypass
Publication date: 2026-04-14
Last updated on: 2026-04-27
Assigner: Microsoft Corporation
Description
Description
Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| microsoft | powershell | From 7.4 (inc) to 7.4.14 (exc) |
| microsoft | powershell | From 7.5 (inc) to 7.5.5 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-20 | The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. |