Executive brief
Devolutions PowerShell Universal is an IT automation platform used for scripting and orchestration. A security flaw in the automation jobs API allows certain authorized users to see sensitive OAuth refresh tokens belonging to other users. This could allow an attacker to gain unauthorized access to external services linked to those accounts.
Technical details
An information disclosure vulnerability (CWE-201) exists in the automation jobs API of Devolutions PowerShell Universal. The root cause is a failure to strip sensitive OAuth refresh tokens from API responses when a user requests job details. An authenticated attacker with scoped 'job read' or 'script read' permissions can exploit this to obtain the refresh tokens of other users. This could lead to session hijacking or unauthorized access to third-party services integrated via OAuth. The issue is fixed in version 2026.2.3.
Affected products
- Devolutions PowerShell Universal 2026.2.2 and earlier
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory