Devolutions
Devolutions Powershell Universal: vulnerabilities and CVEs
Devolutions Powershell Universal has 8 published vulnerabilities, 8 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs8
Last 12 months8
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92237 | Medium (6.5) | 0.37% | — | Sep 15, 2026 | Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application… |
| CVE-2026-19768 | High (8.1) | 0.39% | — | Aug 14, 2026 | Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute… |
| CVE-2026-16802 | Medium (6.5) | 0.10% | — | Jul 24, 2026 | Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored… |
| CVE-2026-16801 | High (8.8) | 0.53% | — | Jul 24, 2026 | Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute… |
| CVE-2026-16800 | High (8.8) | 0.53% | — | Jul 24, 2026 | Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute… |
| CVE-2026-16799 | Medium (5) | 0.25% | — | Jul 24, 2026 | Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and… |
| CVE-2026-16798 | Medium (6.5) | 0.38% | — | Jul 24, 2026 | Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain… |
| CVE-2026-13437 | Medium (6.5) | 0.44% | — | Jun 29, 2026 | Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially… |