Notepad++ · Notepad++ · CVE-2026-46710
**Name of the Vulnerable Software and Affected Versions**
Notepad++ versions 8.9.4 through 8.9.5
**Description**
The installer contains a local privilege escalation issue. During the installation process, the installer invokes `powershell.exe` without specifying an absolute path after setting the working directory to the installation contextMenu directory. An attacker can exploit this by placing a malicious `powershell.exe` file in a user-writable custom installation directory. If a privileged user subsequently runs the installer and selects that specific directory, the malicious executable is launched with the elevated privileges of the installer.
**Recommendations**
Update to version 8.9.6.