CVE-2026-16799

MEDIUM

Devolutions PowerShell Universal < 2026.2.3 - Missing Authorization

Title source: rule
STIX 2.1

Description

Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks.

References (1)

Core 1

Scores

CVSS v3 5.0
EPSS 0.0015
EPSS Percentile 4.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
Devolutions/PowerShell Universal < 2026.2.3
devolutions/powershell_universal < 2026.2.3.0
Published Jul 24, 2026
Tracked Since Jul 24, 2026