CVE-2026-16801

Devolutions · PowerShell Universal

A code injection vulnerability in the variables feature of Devolutions PowerShell Universal allows authenticated users to execute arbitrary code.

Executive summary

A high-severity code injection vulnerability in Devolutions PowerShell Universal allows authenticated attackers to achieve remote code execution.

Vulnerability

The application fails to properly sanitize input within its variables feature, leading to a CWE-94 code injection vulnerability. This flaw requires the attacker to have low-level authenticated access to the system to successfully execute arbitrary code.

Business impact

A successful exploit could allow an attacker to execute arbitrary commands with the privileges of the PowerShell Universal service. This could lead to a full compromise of the underlying server, unauthorized access to sensitive automation scripts, and potential lateral movement within the network. With a CVSS score of 8.8, this vulnerability poses a significant risk to the integrity and availability of critical IT infrastructure.

Remediation

Immediate Action: Update Devolutions PowerShell Universal to version 2026.2.3 or later immediately.

Proactive Monitoring: Review system logs for unusual process execution or PowerShell script modifications. Audit the variables feature for unexpected or unauthorized entries.

Compensating Controls: Restrict access to the PowerShell Universal management interface to trusted internal networks only, and enforce strict principle of least privilege for all user accounts.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The severity of this flaw necessitates immediate attention. Administrators must prioritize patching to version 2026.2.3 to eliminate the risk of remote code execution. Failure to patch leaves the environment vulnerable to internal actors or compromised accounts capable of escalating their privileges to full system control.