CVE-2026-26143: Microsoft PowerShell Security Feature Bypass Vulnerability
Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
Other sources
Microsoft PowerShell Security Feature Bypass Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.5.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.4.14
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26143?
CVE-2026-26143 is rated as a medium severity vulnerability due to the risk of unauthorized access.
What impact does CVE-2026-26143 have?
CVE-2026-26143 allows an unauthorized attacker to bypass a security feature locally in Microsoft PowerShell.
How do I fix CVE-2026-26143?
To remediate CVE-2026-26143, users should update to the latest version of Microsoft PowerShell.
Which versions of PowerShell are affected by CVE-2026-26143?
CVE-2026-26143 affects Microsoft PowerShell 7.4 and 7.5.
Is there a known exploit for CVE-2026-26143?
As of now, there have been no public exploits reported for CVE-2026-26143.