CyberRota Analysis
AI-GeneratedDevolutions PowerShell Universal versions 2026.2.3 and earlier are vulnerable to code injection due to improper handling of settings, allowing authenticated users with management permissions to execute arbitrary PowerShell code. This vulnerability poses a significant risk as it can lead to unauthorized access and control over the system. Organizations using affected versions should prioritize patching to mitigate potential exploitation.
Original NVD Description
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the settings configuration file.