SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-16799

MEDIUM · CVSS 5 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

Devolutions PowerShell Universal versions 2026.2.2 and earlier are vulnerable due to improper access control, allowing authenticated users with only the Reader role to execute automation tests and alter workflow properties. This flaw arises from inadequate server-side authorization checks, potentially leading to unauthorized actions within the application. Organizations using affected versions should prioritize remediation to mitigate risks associated with unauthorized access and manipulation of automation workflows.

CVE
CVE-2026-16799
Severity
MEDIUM
CVSS
5
EPSS
0.15%

Original NVD Description

Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks.

Related CVEs

Other vulnerabilities affecting the same vendor(s)