CVE-2026-13437: Medium severity Devolutions PowerShell Universal vulnerability
Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in plaintext in job API responses.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13437?
The severity of CVE-2026-13437 is rated at 55, indicating a medium risk level.
How do I fix CVE-2026-13437?
To fix CVE-2026-13437, upgrade to a patched version of Devolutions PowerShell Universal that addresses this vulnerability.
What causes CVE-2026-13437?
CVE-2026-13437 is caused by the insertion of sensitive information into sent data within the AI Agent job API.
Who is affected by CVE-2026-13437?
Authenticated users with AI Agent read access in Devolutions PowerShell Universal version 2026.2.0 are affected by CVE-2026-13437.
What are the potential impacts of CVE-2026-13437?
CVE-2026-13437 allows an attacker to obtain reusable authentication tokens due to sensitive data being serialized in plaintext.