CVE-2026-58612: PowerShell Information Disclosure Vulnerability
PowerShell Information Disclosure Vulnerability
Other sources
Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.6.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.4.19.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.5.10.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58612?
CVE-2026-58612 has a severity rating of 7.4, classified as high.
How does CVE-2026-58612 affect PowerShell?
CVE-2026-58612 allows unauthorized attackers to disclose information via a server-side request forgery vulnerability in Microsoft PowerShell Core.
What versions of PowerShell are affected by CVE-2026-58612?
CVE-2026-58612 affects Microsoft PowerShell versions 7.4, 7.5, and 7.6.
How do I fix CVE-2026-58612?
To address CVE-2026-58612, upgrade to the patched version of Microsoft PowerShell as provided by Microsoft.
What type of vulnerability is CVE-2026-58612 classified as?
CVE-2026-58612 is classified as a server-side request forgery (SSRF) vulnerability.