CVE-2026-4064: High severity Ironmagma PowerShell Universal vulnerability
Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perform privileged operations — including reading sensitive data, creating or deleting resources, and disrupting service operations — via crafted gRPC requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4064?
CVE-2026-4064 has a high severity rating due to the potential for unauthorized access to sensitive data and resources.
How do I fix CVE-2026-4064?
To mitigate CVE-2026-4064, update PowerShell Universal to version 2026.1.4 or later.
What systems are affected by CVE-2026-4064?
CVE-2026-4064 affects Ironmagma PowerShell Universal versions prior to 2026.1.4.
What type of vulnerability is CVE-2026-4064?
CVE-2026-4064 is a vulnerability related to missing authorization checks in multiple gRPC service endpoints.
What impacts can CVE-2026-4064 have on an organization?
CVE-2026-4064 can allow authenticated users to perform privileged operations, potentially exposing sensitive data and resource management.