Description
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw originates from improper control of code generation in Microsoft PowerShell (CWE‑94), enabling an attacker with local access to inject and run arbitrary code that can circumvent the built‑in security feature. The result is a local bypass of the security mechanism, which could allow further malicious actions on the affected system.

Affected Systems

Microsoft PowerShell versions 7.4, 7.5, and 7.6 are affected by this vulnerability. No other vendors or products are listed as impacted.

Risk and Exploitability

The CVSS score of 7.8 categorizes the issue as high severity, while an EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not included in CISA’s KEV catalog. Attackers would need local access to craft and execute malicious PowerShell code; the description infers that the feature is bypassed through local code injection.

Generated by OpenCVE AI on August 12, 2026 at 14:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft security update for PowerShell 7.4, 7.5, or 7.6 as referenced on the Microsoft Security Response Center advisory.
  • Verify that the PowerShell execution policy and other security features are enabled after applying the update to ensure the bypass protection is active.
  • Review and remove any custom scripts or policies that could be abused for code injection, and monitor for anomalous PowerShell execution patterns.

Generated by OpenCVE AI on August 12, 2026 at 14:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:powershell:*:*:*:*:*:*:*:*

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
Title Microsoft PowerShell Security Feature Bypass Vulnerability
First Time appeared Microsoft
Microsoft powershell
Weaknesses CWE-94
CPEs cpe:2.3:a:microsoft:powershell:*:-:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft powershell
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Powershell
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:07:58.850Z

Reserved: 2026-08-04T00:04:56.036Z

Link: CVE-2026-70338

cve-icon Vulnrichment

Updated: 2026-08-11T17:48:25.543Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:19:11.520

Modified: 2026-08-14T17:09:32.087

Link: CVE-2026-70338

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:30:34Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')