CVE-2026-46710Disclosure(notepad-plus-plus / notepad\+\+)

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Notepad++ is a free and open-source source code editor. From 8.9.4 until 8.9.6, Notepad++ contains a local privilege escalation vulnerability in the installer. During installation, the installer invokes powershell.exe without using an absolute path after setting the working directory to the installation contextMenu directory. If an attacker can pre-place a malicious powershell.exe in a user-writable custom installation directory, and a privileged user later runs the installer and selects that directory, the attacker-controlled executable is launched with the elevated privileges of the installer. This vulnerability is fixed in 8.9.6.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-426

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • notepad\+\+

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
notepad\+\+

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-27: 2Technical Details · 2026-06-27: 206-27
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-46710 Notepad++ is a free and open-source source code editor. From 8.9.4 until 8.9.6, Notepad++ contains a local privilege escalation vulnerability in the installer. During… https://www.cve.org/CVERecord?id=CVE-2026-46710

    Post summary

    An announcement of a local privilege escalation flaw in Notepad++ installers between versions 8.9.4 and 8.9.6.

    01020968
    58.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-46710 Notepad++ is a free and open-source source code editor. From 8.9.4 until 8.9.6, Notepad++ contains a local privilege escalation vulnerability in the installer. During… https://www.cve.org/CVERecord?id=CVE-2026-46710 ----- Traducción: CVE-2026-46710 Not… http://infoflow.cloud`

    Post summary

    CVE-2026-46710 is a disclosed local privilege escalation vulnerability in Notepad++ installers (8.9.4‑8.9.6), with no known PoC, exploitation, or patch mentioned.

    0001037
    89 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnotepad-plus-plusnotepad\+\+---

Explore more