SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-16798

MEDIUM · CVSS 6.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

Devolutions PowerShell Universal versions 2026.2.2 and earlier are vulnerable due to improper handling of sensitive information in the automation jobs API, allowing authenticated users with specific read permissions to access another user's OAuth refresh token. This exposure could lead to unauthorized access to user accounts and sensitive data. Organizations using affected versions should prioritize patching to mitigate potential security risks.

CVE
CVE-2026-16798
Severity
MEDIUM
CVSS
6.5
EPSS
0.22%

Original NVD Description

Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token.

Related CVEs

Other vulnerabilities affecting the same vendor(s)