Summary

A path traversal vulnerability in Windows PowerShell allows an unauthenticated attacker to bypass path validation safeguards over a network. Successful exploitation circumvents the security checks that restrict which files may be modified and that require user approval for sensitive locations, allowing changes to protected files without the user’s knowledge or consent.

The attack requires user interaction but no authentication. The impact is limited to integrity — an attacker can modify protected files but cannot read arbitrary files or cause denial of service through this vulnerability alone.

This vulnerability was discovered by Aretiq AI and responsibly disclosed to Microsoft, who addressed it in the September 2026 Patch Tuesday security updates. Microsoft has credited ECooper with Aretiq.AI for reporting this vulnerability in their security advisory.

Affected Versions

ProductBuildPatch
Windows 11 Version 26H1 (x64, ARM64)10.0.28000.2954KB5124012
Windows 11 Version 25H2 (x64, ARM64)10.0.26200.9445KB5124008
Windows 11 Version 24H2 (x64, ARM64)10.0.26100.9445KB5124008
Windows 11 Version 23H2 (x64, ARM64)10.0.22631.7582KB5122880
Windows 10 Version 22H2 (x64, ARM64, 32-bit)10.0.19045.7725KB5122878
Windows 10 Version 21H2 (x64, ARM64, 32-bit)10.0.19044.7725KB5122878
Windows 10 Version 1809 (x64, 32-bit)10.0.17763.9245KB5122876
Windows 10 Version 1607 (x64, 32-bit)10.0.14393.9512KB5123099
Windows Server 202510.0.26100.33438KB5122871
Windows Server 202210.0.20348.5622KB5122882
Windows Server 201910.0.17763.9245KB5122876
Windows Server 201610.0.14393.9512KB5123099
Windows Server 2012 R2 (ESU)6.3.9600.23397KB5123066
Windows Server 2012 (ESU)6.2.9200.26349KB5123065

Remediation

Apply the corresponding cumulative security update for your Windows version. Updates require a system restart.

Timeline

DateEvent
2026-05-23Vulnerability submitted to Microsoft
2026-05-26Microsoft opens case
2026-09-04Microsoft confirms the behavior
2026-09-08Microsoft releases security update (September 2026 Patch Tuesday)
2026-09-09Advisory published

References