Back to CVE List

CVE-2026-16799

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
5.0 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

Vulnerability Description

Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-862
Source
NVD
Vendor
Devolutions
Product
PowerShell Universal

External References

Discussion (0)

Add Comment

No comments yet. Be the first!