CVE-2026-8694: Improper access control on the API documentation endpoint in PowerShell Universal
Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST endpoints.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Require authentication and proper authorization for access to the API documentation/OpenAPI endpoints so unauthenticated users cannot retrieve the OpenAPI specification for user-defined REST endpoints; disable publishing of the OpenAPI spec if not required.
Devolutions PowerShell Universal API documentation (OpenAPI) endpoint access control = require authentication and authorization - Compensating control
Restrict network access to the API documentation/OpenAPI endpoint (for example via firewall rules, WAF, or limiting to internal/trusted IP ranges/VPN) to prevent unauthenticated remote access to the OpenAPI specification.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8694?
CVE-2026-8694 has a medium severity rating of 5.3.
What vulnerability does CVE-2026-8694 address?
CVE-2026-8694 addresses improper access control on the API documentation endpoint in Devolutions PowerShell Universal.
How do I fix CVE-2026-8694?
To fix CVE-2026-8694, upgrade to Devolutions PowerShell Universal version 2026.1.8 or later.
What are the potential risks of CVE-2026-8694?
CVE-2026-8694 allows unauthenticated remote attackers to access the OpenAPI specification of user-defined REST endpoints.
Which versions of Devolutions PowerShell Universal are affected by CVE-2026-8694?
CVE-2026-8694 affects Devolutions PowerShell Universal version 2026.1.7 and earlier.