Executive brief
Devolutions PowerShell Universal, a platform used to automate IT tasks and host custom dashboards, contains a security flaw that allows unauthorized individuals to view internal API documentation. An attacker can access the OpenAPI specifications for custom-defined endpoints without logging in. This could expose information about the structure and functionality of a company's internal automation tools, potentially aiding in further targeted attacks.
Technical details
An improper access control vulnerability (CWE-306) exists in the API documentation endpoint of Devolutions PowerShell Universal versions 2026.1.7 and earlier. The flaw allows a remote, unauthenticated attacker to retrieve the OpenAPI specification for user-defined REST endpoints. This occurs because the application fails to enforce authentication requirements on the documentation endpoint. By accessing this specification, an attacker can gain detailed knowledge of available API routes, expected parameters, and data structures, which facilitates reconnaissance for further exploitation. The issue is resolved in PowerShell Universal version 2026.2.0.
Affected products
- Devolutions PowerShell Universal 2026.1.7 and earlier
Timeline
- 2026-06-12: disclosed
- 2026-06-12: advisory
- 2026-06-12: patched: Fixed in version 2026.2.0