CVE-2026-19768

8.1

Devolutions · PowerShell Universal

Devolutions PowerShell Universal contains a code injection vulnerability in the settings feature that can be exploited by authenticated users.

Executive summary

Devolutions PowerShell Universal versions prior to 2026.2.4 are vulnerable to code injection, which could lead to unauthorized system command execution.

Vulnerability

The application improperly controls the generation of code within its settings feature (CWE-94). An authenticated attacker can inject malicious code, which is then executed by the server with the privileges of the application.

Business impact

A code injection vulnerability represents a severe threat to the confidentiality, integrity, and availability of the hosting environment. By executing arbitrary code, an attacker could gain full control over the server, access sensitive configuration data, or pivot into the broader network. The CVSS score of 8.1 reflects the high potential for impact on enterprise systems.

Remediation

Immediate Action: Update Devolutions PowerShell Universal to version 2026.2.4 or later immediately.

Proactive Monitoring: Monitor server logs for unexpected process execution or modifications to application configuration files.

Compensating Controls: Ensure the application runs with the least privilege necessary, and utilize a Web Application Firewall to block suspicious input patterns in settings requests.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The risk of code injection in management software is critical. Administrators must verify their current version and apply the vendor-provided update to version 2026.2.4 as soon as possible to prevent potential remote code execution.

More Devolutions CVEs