CVE-2026-50523
published 2026-08-14CVE-2026-50523: Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code…
PriorityP348high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.22%
11.9th percentile
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | powershell | >= 7.4 < 7.4.19.0 | 7.4.19.0 |
| microsoft | powershell | >= 7.5 < 7.5.10.0 | 7.5.10.0 |
| microsoft | powershell | >= 7.6 < 7.6.5 | 7.6.5 |
| microsoft | powershell_7.4 | >= 7.4.0 < 7.4.19.0 | 7.4.19.0 |
| microsoft | powershell_7.5 | >= 7.5.0 < 7.5.10.0 | 7.5.10.0 |
| microsoft | powershell_7.6 | >= 7.6.0 < 7.6.5 | 7.6.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.
ghsa_unreviewed·2026-08-14
CVE-2026-50523 [HIGH] CWE-77 Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.
VulDB
Microsoft PowerShell 7.4/7.5/7.6 command injection
vuldb·2026-08-14·CVSS 7.8
CVE-2026-50523 [HIGH] Microsoft PowerShell 7.4/7.5/7.6 command injection
A vulnerability was found in Microsoft PowerShell 7.4/7.5/7.6. It has been declared as problematic. This issue affects some unknown processing. Executing a manipulation can lead to command injection.
This vulnerability is registered as CVE-2026-50523. The attack needs to be launched locally. No exploit is available.
A patch should be applied to remediate this issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-14
Published