CVE-2026-26170
vulnerability analysis and mitigation

Overview

CVE-2026-26170 is a local privilege escalation vulnerability caused by improper input validation in Microsoft PowerShell, allowing an authorized low-privileged attacker to elevate privileges on the local system. It was disclosed and patched on April 14, 2026, as part of Microsoft's April 2026 Patch Tuesday release, which addressed 167 flaws. Affected platforms span a wide range of Windows versions, including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, 2022 23H2, and Windows Server 2025. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).

Technical details

The root cause is classified as CWE-20 (Improper Input Validation) within Microsoft PowerShell's handling of locally supplied input. The attack vector is local, requiring an attacker to already possess low-level authenticated access to the target system; no network access or user interaction is needed. By supplying specially crafted input to a vulnerable PowerShell component, the attacker can bypass privilege boundaries and escalate to SYSTEM-level access. No public technical write-ups or proof-of-concept code detailing the specific vulnerable code path have been published as of the time of this report (Microsoft MSRC, Feedly).

Impact

Successful exploitation allows a local attacker with low privileges to escalate to SYSTEM-level administrative control of the affected Windows host, resulting in high confidentiality, integrity, and availability impact. An attacker achieving SYSTEM privileges can read or exfiltrate sensitive data, modify or destroy system files, disable security controls, and potentially use the compromised host as a pivot point for lateral movement within the network. The scope is limited to the affected system (unchanged scope), but full system compromise represents a critical post-exploitation outcome (Microsoft MSRC, Feedly).

Exploitability

As of the time of this report, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.088%, indicating a low near-term probability of exploitation. No threat actor attribution has been reported in connection with this CVE.

Mitigation and workarounds

Microsoft released patches on April 14, 2026, addressing this vulnerability across all affected platforms. Administrators should apply the relevant cumulative updates to bring systems to the following minimum build versions: Windows 10 21H2 → 10.0.19044.7184, Windows 10 22H2 → 10.0.19045.7184, Windows 10 1809 → 10.0.17763.8644, Windows 11 23H2 → 10.0.22631.6936, Windows 11 24H2 → 10.0.26100.8246 (or 10.0.26100.32690 for Server 2025), Windows 11 25H2 → 10.0.26200.8246, Windows 11 26H1 → 10.0.28000.1836, Windows Server 2016 → 10.0.14393.9060, Windows Server 2019 → 10.0.17763.8644, Windows Server 2022 → 10.0.20348.5020, Windows Server 2022 23H2 → 10.0.25398.2274. As interim mitigations, organizations should restrict local user account creation, limit administrative access to authorized personnel, and monitor PowerShell execution logs for anomalous privilege escalation activity (Microsoft MSRC).

Community reactions

CVE-2026-26170 was covered as part of broader April 2026 Patch Tuesday roundups by several security outlets. BleepingComputer reported on the overall release of 167 fixes including this vulnerability, and Zero Day Initiative (ZDI) published its April 2026 security update review (BleepingComputer, ZDI Blog). Rapid7 and Sophos also included it in their Patch Tuesday analyses, and Lansweeper published a summary for enterprise asset management teams (Rapid7, Sophos). No notable independent researcher commentary or significant social media discussion specific to this CVE has been observed.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management