Executive brief
Devolutions PowerShell Universal, a platform for automating IT tasks and creating dashboards, contains a vulnerability where sensitive information is stored insecurely. When a secure vault is not configured, the software saves secret variables in plain text on the server's hard drive. This allows any user with local access to the server's file system to read sensitive credentials or configuration secrets, potentially leading to unauthorized access to other systems.
Technical details
A cleartext storage of sensitive information vulnerability (CWE-312) exists in the variables feature of Devolutions PowerShell Universal. The root cause is the application's failure to encrypt secret variables on disk when a vault provider is not explicitly selected by the administrator. A local attacker with file system access can navigate to the variables configuration file and read secret values in plain text. This vulnerability affects versions 2026.2.2 and earlier. Users are advised to upgrade to version 2026.2.3 or higher and ensure a secure vault is configured for secret storage.
Affected products
- Devolutions PowerShell Universal 2026.2.2 and earlier
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory