CVE-2026-26143: Microsoft PowerShell Security Feature Bypass Vulnerability
Published Apr 14, 2026
·Updated
Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
Other sources
Microsoft PowerShell Security Feature Bypass Vulnerability
— Microsoft
Affected Software
5 affected componentsFixes available
Microsoft PowerShell
Microsoft PowerShell 7.4
Microsoft PowerShell 7.5
Microsoft PowerShell>=7.4<7.4.14
Microsoft PowerShell>=7.5<7.5.5
Event History
Apr 14, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·04:57 PM
Data Sourced
via MITRE·04:57 PM
DescriptionSeverity
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-26143?
CVE-2026-26143 is rated as a medium severity vulnerability due to the risk of unauthorized access.
2
What impact does CVE-2026-26143 have?
CVE-2026-26143 allows an unauthorized attacker to bypass a security feature locally in Microsoft PowerShell.
3
How do I fix CVE-2026-26143?
To remediate CVE-2026-26143, users should update to the latest version of Microsoft PowerShell.
4
Which versions of PowerShell are affected by CVE-2026-26143?
CVE-2026-26143 affects Microsoft PowerShell 7.4 and 7.5.
5
Is there a known exploit for CVE-2026-26143?
As of now, there have been no public exploits reported for CVE-2026-26143.