Sploitus

CVE-2026-46710

No indexed exploits for CVE-2026-46710 yet

Notepad++ is a free and open-source source code editor. From 8.9.4 until 8.9.6, Notepad++ contains a local privilege escalation vulnerability in the installer. During installation, the installer invokes powershell.exe without using an absolute path after setting the working directory to the installation contextMenu directory. If an attacker can pre-place a malicious powershell.exe in a user-writable custom installation directory, and a privileged user later runs the installer and selects that directory, the attacker-controlled executable is launched with the elevated privileges of the installer. This vulnerability is fixed in 8.9.6.

Affected products
Notepad++
Notepad-plus-plus Notepad\+\+
< 8.9.6
Fix
Available
CVSS 3.1
7.8 HIGH
EPSS
0.1% (1th percentile)
Weakness
CWE-426
NVD status
Analyzed
Published
2026-06-26
CVE-2026-46710 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-46710 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-46710 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.