Improper Access Control in Devolutions PowerShell Universal Affects Automation Features
CVE-2026-16799
Currently unrated
What is CVE-2026-16799?
An improper access control vulnerability has been identified in Devolutions PowerShell Universal, affecting version 2026.2.2 and earlier. This flaw allows authenticated users with only the Reader role to execute automation tests and modify workflow properties due to the absence of necessary server-side authorization checks. This lack of proper authorization can lead to unauthorized actions that could impact the integrity and security of automated workflows.
Affected Version(s)
PowerShell Universal 0 < 2026.2.3
