CVE-2026-70338: Microsoft PowerShell Security Feature Bypass Vulnerability
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
Other sources
Microsoft PowerShell Security Feature Bypass Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.6.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.4.19.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.5.10.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70338?
CVE-2026-70338 has a high severity rating of 7.8.
How do I fix CVE-2026-70338?
To mitigate CVE-2026-70338, ensure that all affected versions of Microsoft PowerShell are updated to the latest security patches.
What type of vulnerability is CVE-2026-70338?
CVE-2026-70338 is classified as a code injection vulnerability due to improper control of code generation.
What software is affected by CVE-2026-70338?
CVE-2026-70338 affects Microsoft PowerShell, including versions 7.4, 7.5, and 7.6.
How can CVE-2026-70338 impact a system?
CVE-2026-70338 allows an unauthorized attacker to bypass security features locally, potentially compromising system integrity.