CVE-2026-58612: PowerShell Information Disclosure Vulnerability

Overview

Severity
High (CVSS 7.4)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
Category
Information Disclosure
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Aug
Released
2026-08-11

Description

Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.

FAQ

What type of information could be disclosed by this vulnerability? Exploiting this vulnerability could allow the disclosure of credentials.

Affected Products (3)

Developer Tools

  • PowerShell 7.5
  • PowerShell 7.4
  • PowerShell 7.6

Acknowledgments

NavSec, <a href="https://zpbrent.github.io/">Peng Zhou (zpbrent)</a>, Joseph Semaan, <a href="https://github.com/sleepystew/">Michael Curtis</a>, <a href="https://www.linkedin.com/in/charlievogt">Charlie Vogt</a>, <a href="https://x.com/hasanfleyah">HASAN FLAYYIH ABDULLAH</a>, PuH4ck3rX, <a href="https://puh4ck3rx.github.io/">PuH4ck3rX</a> with W&amp;M, Anonymous, Lucas Futures, <a href="https://x.com/valzevul">Vadim Drobinin (@valzevul)</a> with <a href="https://drobinin.com/">Drobinin Limited</a>, Damian Regulski, <a href="https://linkedin.com/in/cybera">Amar Khatri</a>, <a href="https://www.linkedin.com/in/mohit-negi-b9b5711a2y">Mohit_Negi</a> with <a href="https://bugcrowd.com/mohit_negi">Bugcrowd</a>, <a href="https://www.linkedin.com/in/yogi-atram/">Yogi Atram</a>, <a href="https://www.linkedin.com/in/alnnajafi/">AL Najafi</a>, <a href="https://x.com/ayatoshitomi">Ayato</a>, <a href="https://www.linkedin.com/in/krithik-babu-p-bb97431a9/">Krithik Babu P (DarkLycn1976)</a>, <a href="https://www.linkedin.com/in/alnnajafi/">AL Najafi</a>

Revision History

  • 2026-08-11: Information published.