SEPTEMBER 12, 2026
Live Feed
Back to database
Case File

CVE-2026-16801

HIGH · CVSS 8.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

Devolutions PowerShell Universal versions 2026.2.2 and earlier are vulnerable to code injection due to improper handling of variable values, allowing authenticated users with write permissions to execute arbitrary PowerShell code. This vulnerability poses a significant risk as it can lead to unauthorized access and control over the system. Organizations using affected versions should prioritize remediation to mitigate potential exploitation.

CVE
CVE-2026-16801
Severity
HIGH
CVSS
8.8
EPSS
0.29%

Original NVD Description

Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the variables configuration file.

Related CVEs

Other vulnerabilities affecting the same vendor(s)