CVE-2026-3563: Input Validation
Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes, resulting in unintended request routing and denial of service via a conflicting URL path.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3563?
CVE-2026-3563 has a high severity rating due to the potential for unauthorized request routing and denial of service.
How do I fix CVE-2026-3563?
To fix CVE-2026-3563, upgrade PowerShell Universal to version 2026.1.4 or later to ensure proper input validation.
Who is affected by CVE-2026-3563?
Authenticated users with permissions to create or modify Apps or Endpoints in PowerShell Universal prior to version 2026.1.4 are affected by CVE-2026-3563.
What are the potential impacts of CVE-2026-3563?
CVE-2026-3563 can cause unintended request routing and denial of service, impacting application availability.
Where can I find more information about CVE-2026-3563?
Further details about CVE-2026-3563 can be found in security advisories and vulnerability databases.