Junglewise Threat Intelligence

CVE-2026-16801: Devolutions PowerShell Universal code injection in variables feature

CVE-2026-16801 · Severity: info · CVSS 8.7 · Published 2026-07-24

Technologies: Devolutions PowerShell Universal. Vendors: Devolutions.

Executive brief

Devolutions PowerShell Universal is an automation platform used to manage IT tasks, dashboards, and APIs. A vulnerability in the variables feature allows an authorized user to execute unauthorized commands on the underlying system. This could lead to a full system compromise, data theft, or disruption of automated IT operations.

Technical details

A code injection vulnerability (CWE-94) exists in the variables feature of Devolutions PowerShell Universal versions 2026.2.2 and earlier. The root cause is improper escaping of variable values when they are written to the variables configuration file. An authenticated attacker with 'variable write' permissions can provide a specially crafted variable value that, when processed, executes arbitrary PowerShell code in the context of the application. This allows for full remote code execution on the host. The issue is resolved in version 2026.2.3.

Affected products

  • Devolutions PowerShell Universal 2026.2.2 and earlier

Timeline

  • 2026-07-24: advisory: Initial publication of DEVO-2026-0025
  • 2026-07-24: disclosed

References

Related threats