CVE-2026-16800
Devolutions · PowerShell Universal
An authenticated code injection vulnerability in the schedule feature of Devolutions PowerShell Universal allows attackers with lower-level access to execute arbitrary code.
Executive summary
An authenticated code injection vulnerability in Devolutions PowerShell Universal versions prior to 2026.2.3 poses a severe risk of arbitrary code execution.
Vulnerability
This is a code injection vulnerability (CWE-94) in the schedule feature. The vulnerability requires the attacker to be authenticated with low-level privileges to successfully execute arbitrary code within the application environment.
Business impact
The CVSS score of 8.8 reflects the high severity of this flaw. By injecting and executing arbitrary code, an attacker could escalate privileges, exfiltrate sensitive data, or gain persistent control over the PowerShell Universal instance, leading to a total breach of the application's integrity and confidentiality.
Remediation
Immediate Action: Upgrade to Devolutions PowerShell Universal version 2026.2.3 or later to remediate the vulnerable scheduling component.
Proactive Monitoring: Audit logs for suspicious activity related to scheduled tasks or unexpected PowerShell process execution initiated by the application service account.
Compensating Controls: Implement strict role-based access control (RBAC) to limit the number of users who can interact with the scheduling features until the patch is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a significant risk to administrative infrastructure. Immediate patching to version 2026.2.3 is required to eliminate the code injection vector and secure the application environment.