Junglewise Threat Intelligence

CVE-2026-16800: Devolutions PowerShell Universal code injection in schedule feature

CVE-2026-16800 · Severity: info · CVSS 7.7 · Published 2026-07-24

Technologies: Devolutions PowerShell Universal. Vendors: Devolutions.

Executive brief

Devolutions PowerShell Universal is an automation platform used by IT teams to manage scripts, dashboards, and APIs. A security flaw in the scheduling feature allows an authorized user to run unauthorized commands on the underlying system. This could lead to a full system takeover, data theft, or disruption of automated IT operations.

Technical details

A code injection vulnerability exists in the schedule feature of Devolutions PowerShell Universal versions 2026.2.2 and earlier. The flaw is caused by improper control of code generation when schedule parameter names are concatenated into a script invocation without sufficient sanitization. An authenticated attacker with permissions to create schedules can exploit this by crafting malicious parameter names to execute arbitrary PowerShell code. This vulnerability is tracked as CVE-2026-16800 and has been addressed in version 2026.2.3.

Affected products

  • Devolutions PowerShell Universal 2026.2.2 and earlier

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory
  • 2026-07-24: patched: Fixed in version 2026.2.3

References

Related threats