VDB
GCVE-110-NCSC-2026-285
GCVE-110-NCSC-2026-285
Advisory PublishedCVSS 7.1/10
A server-side request forgery (SSRF) vulnerability in Microsoft PowerShell Core allows unauthorized attackers to disclose information over a network, potentially exposing sensitive data.
Weaknesses (CWE)
CWE-918Server-Side Request Forgery (SSRF)CWE-276Incorrect Default PermissionsCWE-94Improper Control of Generation of Code ('Code Injection')CWE-23Relative Path TraversalCWE-639Authorization Bypass Through User-Controlled KeyCWE-862Missing AuthorizationCWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-863Incorrect AuthorizationCWE-636Not Failing Securely ('Failing Open')CWE-190Integer Overflow or WraparoundCWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')CWE-212Improper Removal of Sensitive Information Before Storage or TransferCWE-606Unchecked Input for Loop ConditionCWE-829Inclusion of Functionality from Untrusted Control SphereCWE-248Uncaught ExceptionCWE-122Heap-based Buffer OverflowCWE-787Out-of-bounds Write
Risk Scores
CVSS 3.1
7.1/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L/E:U/RL:O/RC:C
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Microsoft | vers:unknown/* | — | — |
Aliases
CVE-2026-47285CVE-2026-54981CVE-2026-58612CVE-2026-58641CVE-2026-58650CVE-2026-59113CVE-2026-59119CVE-2026-62871CVE-2026-62872CVE-2026-62886CVE-2026-62897CVE-2026-62899CVE-2026-62900CVE-2026-62901CVE-2026-62902CVE-2026-62909CVE-2026-65675CVE-2026-65810CVE-2026-69278CVE-2026-69306CVE-2026-69320CVE-2026-70335CVE-2026-70336CVE-2026-70337CVE-2026-70338CVE-2026-70354
Browse GCVE Records
3,530 records in the GCVE database · Updated September 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.