Executive brief
Devolutions PowerShell Universal, a platform for automating IT tasks and building web dashboards, contains a security flaw in its automation testing and workflow management features. An authenticated user who should only have 'read-only' access can bypass security checks to execute automation tests and modify workflow settings. This could allow unauthorized users to trigger administrative tasks or disrupt established IT automation processes.
Technical details
A missing authorization vulnerability (CWE-862) exists in the automation tests and workflows features of Devolutions PowerShell Universal. The root cause is a failure to perform adequate server-side authorization checks on incoming requests. An attacker with valid credentials and the 'Reader' role can exploit this to perform actions typically reserved for higher-privileged roles, such as executing tests or altering workflow configurations. The vulnerability is addressed in version 2026.2.3.
Affected products
- Devolutions PowerShell Universal 2026.2.2 and earlier
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory