CVE-2026-3277

PowerShell Universal <2026.1.3 - Info Disclosure

Title source: llm

Description

The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/authentication.ps1 script, which allows an attacker with read access to that file to obtain the OIDC client credentials

Scores

EPSS 0.0001
EPSS Percentile 1.3%

Classification

CWE
CWE-312
Status draft

Timeline

Published Feb 27, 2026
Tracked Since Feb 27, 2026