Improper Access Control in Devolutions PowerShell Universal Affects Automation Features
CVE-2026-16799

5MEDIUM

Key Information:

Vendor
CVE Published:
24 July 2026

What is CVE-2026-16799?

An improper access control vulnerability has been identified in Devolutions PowerShell Universal, affecting version 2026.2.2 and earlier. This flaw allows authenticated users with only the Reader role to execute automation tests and modify workflow properties due to the absence of necessary server-side authorization checks. This lack of proper authorization can lead to unauthorized actions that could impact the integrity and security of automated workflows.

Affected Version(s)

PowerShell Universal 0 < 2026.2.3

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.