Code Injection Vulnerability in Devolutions PowerShell Universal
CVE-2026-19768
8.1HIGH
What is CVE-2026-19768?
In Devolutions PowerShell Universal versions prior to 2026.2.3, a code injection vulnerability arises from improper control of the code generation process. This flaw allows authenticated users with permissions to manage settings to enter crafted values that are inadequately escaped, resulting in arbitrary PowerShell code execution through the configuration file. This vulnerability poses significant risks, enabling potential attackers to execute malicious code and compromise system security.
Affected Version(s)
PowerShell Universal 0 < 2026.2.4
