CVE-2026-16801: Code Injection
Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the variables configuration file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Devolutions PowerShell Universalto a version that resolves this vulnerability.Fixed in 2026.2.2 - Compensating control
Until upgraded, restrict variable write permission so only trusted, authorized users can modify variables (to prevent authenticated code injection via crafted variable values).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16801?
The severity of CVE-2026-16801 is rated as high with a score of 8.8.
How do I fix CVE-2026-16801?
To fix CVE-2026-16801, update to Devolutions PowerShell Universal version 2026.2.3 or later.
What type of vulnerability is CVE-2026-16801?
CVE-2026-16801 is classified as a Code Injection vulnerability.
Who is affected by CVE-2026-16801?
Authenticated users with variable write permissions in Devolutions PowerShell Universal versions 2026.2.2 and earlier are affected by CVE-2026-16801.
What can an attacker do with CVE-2026-16801?
An attacker can execute arbitrary PowerShell code by using crafted variable values that are not properly escaped.