CVE-2026-58612Disclosure(microsoft / powershell)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft powershell systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • powershell

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-08-11); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
powershell

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-11: 1Mentions · 2026-09-11: 1Patch / Workaround · 2026-08-11: 1Technical Details · 2026-08-11: 1Technical Details · 2026-09-11: 108-1109-11
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • HASAN FLAYYIH ABDULLAH@hasanfleyah
    Disclosure

    I discovered CVE-2026-58612, an Authorization header leak in PowerShell Invoke-WebRequest / Invoke-RestMethod. Using -PreserveHttpMethodOnRedirect or -AllowInsecureRedirect can cause PowerShell to forward credentials to a different host after a redirect https://t.co/NiDHiSAT6R

    Post summary

    The user announces a newly discovered CVE-2026-58612, detailing an Authorization header leak in PowerShell that forwards credentials across redirects when using certain flags, without providing a PoC, patch, or evidence of active exploitation.

    0001089
    123 followersView on X
  • Windows Forum@windowsforum
    Disclosure

    ⚠️ Microsoft disclosed a PowerShell info leak but hasn’t published the affected versions. Translation: “Check every install” is the mitigation while admins play PowerShell detective. https://windowsforum.com/security-alerts.84/cve-2026-58612-powershell-flaw-affected-versions-not-published.442492/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #VulnerabilityManagement #PatchManagement #PowershellSecurity https://t.co/INRGEp7xRx

    Post summary

    Microsoft announced a PowerShell info‑leak (CVE‑2026‑58612) but has not released affected versions; the advised mitigation is to inspect all installations.

    0000052
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftpowershell---

Explore more