VDB

GCVE-110-NCSC-2026-285

GCVE-110-NCSC-2026-285
Advisory PublishedCVSS 7.1/10
Vulnetix · Advisory published August 11, 2026
A server-side request forgery (SSRF) vulnerability in Microsoft PowerShell Core allows unauthorized attackers to disclose information over a network, potentially exposing sensitive data.

Weaknesses (CWE)

CWE-918Server-Side Request Forgery (SSRF)CWE-276Incorrect Default PermissionsCWE-94Improper Control of Generation of Code ('Code Injection')CWE-23Relative Path TraversalCWE-639Authorization Bypass Through User-Controlled KeyCWE-862Missing AuthorizationCWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-863Incorrect AuthorizationCWE-636Not Failing Securely ('Failing Open')CWE-190Integer Overflow or WraparoundCWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')CWE-212Improper Removal of Sensitive Information Before Storage or TransferCWE-606Unchecked Input for Loop ConditionCWE-829Inclusion of Functionality from Untrusted Control SphereCWE-248Uncaught ExceptionCWE-122Heap-based Buffer OverflowCWE-787Out-of-bounds Write

Risk Scores

CVSS 3.1
7.1/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L/E:U/RL:O/RC:C

Affected Products

VendorProductVersionsPlatforms
Microsoftvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

3,530 records in the GCVE database · Updated September 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›