CVE-2026-69807
massPath Traversal Privilege Escalation in Windows PowerShell
CVE-2026-69807 is a path traversal flaw (CWE-22) in Windows PowerShell in which a pathname is improperly limited to a restricted directory, allowing input paths to escape the intended directory restriction. It is triggered by an authorized low-privileged attacker with network access who supplies a crafted path that traverses outside the restricted directory; the CVSS vector (PR:L, UI:R) indicates valid credentials and some user interaction are required. A successful attacker gains an elevation of privilege on the target system, with high impact to confidentiality, integrity, and availability. Any Windows environment running the affected Windows PowerShell versions is potentially exposed — the specific affected version ranges are not provided in the available data — though practical exploitation requires an attacker to already hold low-privileged access. As of this analysis there are no reports of exploitation, no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates a 0.9% probability of exploitation within 30 days (57th percentile).
What to do: Apply Microsoft's security update for CVE-2026-69807 when released, and check Microsoft's advisory for the affected version ranges since they are not included in this data. In the interim, restrict who can use PowerShell remoting (e.g., limit WinRM access to trusted administrative users) and ensure low-privilege accounts are not exposed to untrusted network paths, as exploitation requires authorized access.
| Microsoft Windows PowerShell | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.