Summary
A path traversal vulnerability in Windows PowerShell allows an unauthenticated attacker to bypass path validation safeguards over a network. Successful exploitation circumvents the security checks that restrict which files may be modified and that require user approval for sensitive locations, allowing changes to protected files without the user’s knowledge or consent.
The attack requires user interaction but no authentication. The impact is limited to integrity — an attacker can modify protected files but cannot read arbitrary files or cause denial of service through this vulnerability alone.
This vulnerability was discovered by Aretiq AI and responsibly disclosed to Microsoft, who addressed it in the September 2026 Patch Tuesday security updates. Microsoft has credited ECooper with Aretiq.AI for reporting this vulnerability in their security advisory.
Affected Versions
| Product | Build | Patch |
|---|---|---|
| Windows 11 Version 26H1 (x64, ARM64) | 10.0.28000.2954 | KB5124012 |
| Windows 11 Version 25H2 (x64, ARM64) | 10.0.26200.9445 | KB5124008 |
| Windows 11 Version 24H2 (x64, ARM64) | 10.0.26100.9445 | KB5124008 |
| Windows 11 Version 23H2 (x64, ARM64) | 10.0.22631.7582 | KB5122880 |
| Windows 10 Version 22H2 (x64, ARM64, 32-bit) | 10.0.19045.7725 | KB5122878 |
| Windows 10 Version 21H2 (x64, ARM64, 32-bit) | 10.0.19044.7725 | KB5122878 |
| Windows 10 Version 1809 (x64, 32-bit) | 10.0.17763.9245 | KB5122876 |
| Windows 10 Version 1607 (x64, 32-bit) | 10.0.14393.9512 | KB5123099 |
| Windows Server 2025 | 10.0.26100.33438 | KB5122871 |
| Windows Server 2022 | 10.0.20348.5622 | KB5122882 |
| Windows Server 2019 | 10.0.17763.9245 | KB5122876 |
| Windows Server 2016 | 10.0.14393.9512 | KB5123099 |
| Windows Server 2012 R2 (ESU) | 6.3.9600.23397 | KB5123066 |
| Windows Server 2012 (ESU) | 6.2.9200.26349 | KB5123065 |
Remediation
Apply the corresponding cumulative security update for your Windows version. Updates require a system restart.
Timeline
| Date | Event |
|---|---|
| 2026-05-23 | Vulnerability submitted to Microsoft |
| 2026-05-26 | Microsoft opens case |
| 2026-09-04 | Microsoft confirms the behavior |
| 2026-09-08 | Microsoft releases security update (September 2026 Patch Tuesday) |
| 2026-09-09 | Advisory published |