CVE-2026-16800: Code Injection
Published Jul 24, 2026
·Updated
Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names concatenated into a script invocation.
Affected Software
2 affected components
Devolutions PowerShell Universal<=2026.2.2
Devolutions PowerShell Universal<2026.2.3.0
Event History
Jul 24, 2026
CVE Published
via MITRE·02:54 PM
Data Sourced
via MITRE·02:54 PM
DescriptionWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-16800?
CVE-2026-16800 has a high severity score of 8.8.
2
What is the risk associated with CVE-2026-16800?
The risk associated with CVE-2026-16800 is rated at 79.
3
How do I fix CVE-2026-16800?
To fix CVE-2026-16800, upgrade to Devolutions PowerShell Universal version 2026.2.3 or later.
4
What type of vulnerability is CVE-2026-16800?
CVE-2026-16800 is classified as a code injection vulnerability specifically affecting the schedule feature.
5
Who is impacted by CVE-2026-16800?
Authenticated users with schedule creation permissions in Devolutions PowerShell Universal are impacted by CVE-2026-16800.