CVE-2026-16801
Received Received - Intake

Code Injection in Devolutions PowerShell Universal

Vulnerability report for CVE-2026-16801, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: Devolutions Inc.

Description

Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the variables configuration file.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
devolutions powershell_universal to 2026.2.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-16801 is a code injection vulnerability in Devolutions PowerShell Universal versions 2026.2.2 and earlier. It allows an authenticated user with variable write permissions to execute arbitrary PowerShell code by exploiting improperly escaped variable values. These values are written to the variables configuration file without proper sanitization.

Impact Analysis

An attacker with variable write permissions could execute malicious PowerShell code on the affected system. This could lead to unauthorized system access, data theft, or disruption of services. The impact depends on the privileges of the PowerShell Universal instance and the attacker's goals.

Compliance Impact

This vulnerability could lead to unauthorized code execution, potentially compromising sensitive data. This may violate compliance requirements such as GDPR (data protection) or HIPAA (health information security) if personal or health data is exposed or altered. Organizations must remediate this issue to maintain compliance.

Mitigation Strategies

Upgrade to PowerShell Universal version 2026.2.3 or higher to remediate the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16801. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart