Ironmansoftware
Ironmansoftware Powershell Universal: vulnerabilidades y CVE
Ironmansoftware Powershell Universal tiene 8 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses5
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-8694 | Media (5.3) | 0.37% | — | 12 jun 2026 | Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST endpoints. |
| CVE-2026-4064 | Alta (8.3) | 0.38% | — | 17 mar 2026 | Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perform privileged… |
| CVE-2026-3563 | Media (5.5) | 0.40% | — | 17 mar 2026 | Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing… |
| CVE-2026-3277 | Media (6.5) | 0.22% | — | 27 feb 2026 | The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/authentication.ps1 script, which allows an attacker with read… |
| CVE-2026-0618 | Media (6.1) | 0.18% | — | 7 ene 2026 | Cross-site Scripting vulnerability in Devolutions PowerShell Universal.This issue affects Powershell Universal: before 4.5.6, before 5.6.13. |
| CVE-2023-49213 | Alta (8.8) | 2.1% | — | 23 nov 2023 | The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input… |
| CVE-2022-45184 | Alta (7.2) | 2.0% | — | 14 nov 2022 | The Web Server in Ironman Software PowerShell Universal v3.x and v2.x allows for directory traversal outside of the configuration directory, which allows a remote attacker with administrator privilege to create, delete,… |
| CVE-2022-45183 | Alta (8.8) | 0.82% | — | 14 nov 2022 | Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with a valid app token to retrieve other app tokens by ID via an HTTP web request. Patched Versions are… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.