Junglewise Threat Intelligence

CVE-2026-16799: Devolutions PowerShell Universal improper access control in automation tests

CVE-2026-16799 · Severity: info · Published 2026-07-24

Technologies: Devolutions PowerShell Universal. Vendors: Devolutions.

Executive brief

Devolutions PowerShell Universal, a platform for automating IT tasks and building web dashboards, contains a security flaw in its automation testing and workflow management features. An authenticated user who should only have 'read-only' access can bypass security checks to execute automation tests and modify workflow settings. This could allow unauthorized users to trigger administrative tasks or disrupt established IT automation processes.

Technical details

A missing authorization vulnerability (CWE-862) exists in the automation tests and workflows features of Devolutions PowerShell Universal. The root cause is a failure to perform adequate server-side authorization checks on incoming requests. An attacker with valid credentials and the 'Reader' role can exploit this to perform actions typically reserved for higher-privileged roles, such as executing tests or altering workflow configurations. The vulnerability is addressed in version 2026.2.3.

Affected products

  • Devolutions PowerShell Universal 2026.2.2 and earlier

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory

References

Related threats