CVE-2026-50523: Microsoft PowerShell Remote Code Execution Vulnerability

Overview

Severity
High (CVSS 7.8)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Remote Code Execution
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Aug
Released
2026-08-11
Last Updated
2026-08-14

Description

Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.

Affected Products (3)

Developer Tools

  • PowerShell 7.5
  • PowerShell 7.6
  • PowerShell 7.4

Acknowledgments

<a href="https://zpbrent.github.io/">Peng Zhou (zpbrent)</a>, <a href="https://github.com/uchia6861-tech">Abdulkareem Azeez</a>, <a href="https://www.linkedin.com/in/mohit-negi-b9b5711a2y">Mohit_Negi</a> with <a href="https://bugcrowd.com/mohit_negi">Bugcrowd</a>, <a href="https://x.com/hasanfleyah">HASAN FLAYYIH ABDULLAH</a>, <a href="https://twitter.com/tzahpahima">Tzah Pahima</a>, <a href="https://twitter.com/tzahpahima">Tzah Pahima</a>, Rijul JenJen (Breach Guardian,Bavaria Germany), Lucas Futures, <a href="https://github.com/uchia6861-tech">Abdulkareem Azeez</a>, <a href="https://www.linkedin.com/in/brian-linke-2789621a9/">blinke182</a>, Tahira Muhammad with Student @ College of Southern Nevada

Revision History

  • 2026-08-11: Information published.
  • 2026-08-14: The security updates for Powershell have been updated.