PT-2026-52972 · Notepad++ · Notepad++

·

CVE-2026-46710

·

Published

2026-06-26

·

Updated

2026-06-29

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Notepad++ versions 8.9.4 through 8.9.5
Description The installer contains a local privilege escalation issue. During the installation process, the installer invokes powershell.exe without specifying an absolute path after setting the working directory to the installation contextMenu directory. An attacker can exploit this by placing a malicious powershell.exe file in a user-writable custom installation directory. If a privileged user subsequently runs the installer and selects that specific directory, the malicious executable is launched with the elevated privileges of the installer.
Recommendations Update to version 8.9.6.

Exploit

Fix

LPE

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46710
GHSA-6F8F-VMFC-R8C5

Affected Products

Notepad++