CVE-2026-3277
Received
Received - Intake
Cleartext OIDC Client Secret Exposure in PowerShell Universal Authentication
Publication date: 2026-02-27
Last updated on: 2026-03-30
Assigner: Devolutions Inc.
Description
Description
The OpenID Connect (OIDC) authentication configuration in PowerShell
Universal before 2026.1.3 stores the OIDC client secret in cleartext in
the .universal/authentication.ps1 script, which allows an attacker with read access to that file to obtain the OIDC client credentials
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ironmansoftware | powershell_universal | to 2026.1.3 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-312 | The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere. |