CVE-2026-16799
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
5.0 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Vulnerability Description
Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-862
Source
NVD
Vendor
Devolutions
Product
PowerShell Universal
Discussion (0)
Add Comment
No comments yet. Be the first!