CyberRota Analysis
AI-GeneratedDevolutions PowerShell Universal versions 2026.2.2 and earlier are vulnerable due to improper handling of sensitive information in the automation jobs API, allowing authenticated users with specific read permissions to access another user's OAuth refresh token. This exposure could lead to unauthorized access to user accounts and sensitive data. Organizations using affected versions should prioritize patching to mitigate potential security risks.
Original NVD Description
Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token.
Related CVEs
Other vulnerabilities affecting the same vendor(s)