CVE-2026-16798: Medium severity Devolutions PowerShell Universal vulnerability
Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16798?
The severity of CVE-2026-16798 is classified as medium with a score of 6.5.
How do I fix CVE-2026-16798?
To fix CVE-2026-16798, upgrade to Devolutions PowerShell Universal version 2026.2.3 or later.
What are the potential impacts of CVE-2026-16798?
CVE-2026-16798 could allow an authenticated user to access another user's stored OAuth refresh token.
Who is affected by CVE-2026-16798?
Authenticated users with scoped job or script read permission in Devolutions PowerShell Universal 2026.2.2 and earlier are affected.
What type of vulnerability is CVE-2026-16798?
CVE-2026-16798 is an information disclosure vulnerability due to improper handling of sensitive data in the automation jobs API.