CVE-2026-42902

Source
https://cve.org/CVERecord?id=CVE-2026-42902
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42902.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-42902
Published
2026-06-09T17:17:09.670Z
Modified
2026-07-15T06:09:44.574398Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.

References

Affected packages

Git / github.com/microsoft/powertoys

Affected ranges

Type
GIT
Repo
https://github.com/microsoft/powertoys
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:microsoft:powertoys:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.99.1"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

0.*
0.18.0
V0.*
V0.82.1
v0.*
v0.11.0
v0.14.0
v0.14.1
v0.15.0
v0.15.1
v0.16.0
v0.16.1
v0.17.0
v0.18.1
v0.19.0
v0.21.1
v0.25.0
v0.29.0
v0.29.3
v0.31.1
v0.33.1
v0.35.0
v0.37.0
v0.41.2
v0.43.0
v0.47.0
v0.53.1
v0.55.0
v0.56.1
v0.57.0
v0.58.0
v0.59.0
v0.60.0
v0.60.1
v0.61.0
v0.62.0
v0.63.0
v0.64.0
v0.65.0
v0.66.0
v0.67.0
v0.68.0
v0.68.1
v0.69.0
v0.69.1
v0.70.0
v0.70.1
v0.71.0
v0.72.0
v0.73.0
v0.74.0
v0.74.1
v0.75.0
v0.75.1
v0.76.0
v0.76.1
v0.77.0
v0.78.0
v0.79.0
v0.80.0
v0.80.1
v0.81.0
v0.81.1
v0.82.0
v0.82.1
v0.83.0
v0.84.0
v0.84.1
v0.85.0
v0.85.1
v0.86.0
v0.87.0
v0.87.1
v0.88.0
v0.89.0
v0.90.0
v0.91.0
v0.93.0
v0.97.0
v0.97.1
v0.97.2
v0.98.0
v0.99.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42902.json"