CVE-2026-0618: XSS
Published Jan 7, 2026
·Updated
Cross-site Scripting vulnerability in Devolutions PowerShell Universal.This issue affects Powershell Universal: before 4.5.6, before 5.6.13.
Affected Software
3 affected components
Devolutions PowerShell Universal<4.5.6, <5.6.13
Ironmansoftware Powershell Universal<4.5.6
Ironmansoftware Powershell Universal>=5.0.0<5.6.13
Event History
Jan 7, 2026
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-0618?
CVE-2026-0618 is a Cross-site Scripting vulnerability, which can lead to unauthorized access and data manipulation.
2
How do I fix CVE-2026-0618?
To remediate CVE-2026-0618, upgrade Devolutions PowerShell Universal to version 4.5.6 or 5.6.13 or later.
3
What versions of Devolutions PowerShell Universal are affected by CVE-2026-0618?
CVE-2026-0618 affects Devolutions PowerShell Universal versions before 4.5.6 and 5.6.13.
4
Is CVE-2026-0618 a permanent vulnerability?
CVE-2026-0618 is not permanent and can be resolved with the appropriate software update.
5
Who is the vendor for CVE-2026-0618?
The vendor for CVE-2026-0618 is Devolutions, which develops PowerShell Universal.