CVE-2026-26142: Nuance PowerScribe Remote Code Execution Vulnerability
Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
Other sources
Nuance PowerScribe Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2019.8.43.19 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2019.5.14.40 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2019.9.31.23 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2019.4.9.17 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2019.6.36.40 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2023.2.3054 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.212.10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2019.10.36.14 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.154.18 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2023.3.9072 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.197.10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2019.3.16.21 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.111.68 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.11.49 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2019.1.96.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.528.24 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2019.2.9.11 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2019.7.107.26 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.243.19 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.277.28 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.316.12 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.427.15
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26142?
The severity of CVE-2026-26142 is critical with a score of 9.8.
How do I fix CVE-2026-26142?
To mitigate CVE-2026-26142, update to the latest patched version of Microsoft Nuance PowerScribe.
What does CVE-2026-26142 allow an attacker to do?
CVE-2026-26142 allows an unauthorized attacker to execute remote code over a network.
Which software versions are affected by CVE-2026-26142?
CVE-2026-26142 affects various versions of Microsoft Nuance PowerScribe, including PowerScribe One and PowerScribe 360.
What kind of vulnerability is CVE-2026-26142 classified as?
CVE-2026-26142 is classified as a remote code execution vulnerability due to deserialization of untrusted data.