Cleartext Storage Vulnerability in Devolutions PowerShell Universal Software
CVE-2026-16802

6.5MEDIUM

Key Information:

Vendor
CVE Published:
24 July 2026

What is CVE-2026-16802?

The vulnerability allows unauthorized local access to sensitive information stored in cleartext within the variables feature of Devolutions PowerShell Universal. If a vault is not selected, secret values can be easily retrieved by individuals with file system access, presenting a significant risk of exposure and compromise of confidential data.

Affected Version(s)

PowerShell Universal 0 < 2026.2.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.