Sensitive Information Leakage in Devolutions PowerShell Universal Automation Jobs API
CVE-2026-16798
Currently unrated
What is CVE-2026-16798?
An issue in the automation jobs API of Devolutions PowerShell Universal allows authenticated users with specific permissions to inadvertently access another user's OAuth refresh token through job response data. This occurs due to inadequate sanitization of the response, which fails to remove sensitive tokens before transmission.
Affected Version(s)
PowerShell Universal 0 < 2026.2.3
