← Vulnerability feed

Vulnerability record · CVE-2026-50523 · published 14 August 2026

CVE-2026-50523: Microsoft powershell command injection vulnerability

Microsoft · Powershell

Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.

7.8 CVSS 3.1 High EPSS 0.32% · top 77.3% CWE-77 · Command injection
7.8CVSS 3.1 base score
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
18 Aug 2026Last modified by NVD

Description

Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-50523 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-0057Microsoft powershell improper input validation vulnerabilityNET, .NET Framework, and Visual Studio Security Feature Bypass VulnerabilityEPSS 2.8%9.8CVE-2018-8327Microsoft powershell vulnerabilityA remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." Thi…EPSS 22%8.8CVE-2026-70337Microsoft powershell relative path traversal vulnerabilityRelative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.EPSS 0.94%8.5CVE-2022-41076Microsoft PowerShell remote code execution flawCVE-2022-41076 is a remote code execution vulnerability in Microsoft PowerShell affecting Windows client and server releases. The record gives only a…EPSS 61%analysed7.8CVE-2026-70338Microsoft powershell code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locall…EPSS 0.36%7.8CVE-2026-26143Microsoft powershell improper input validation vulnerabilityImproper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.EPSS 0.47%7.8CVE-2022-41121Microsoft powershell vulnerabilityWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 1.1%7.8CVE-2022-26788Microsoft powershell vulnerabilityPowerShell Elevation of Privilege VulnerabilityEPSS 0.65%

Source: NIST National Vulnerability Database (record CVE-2026-50523), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.