CVE-2026-16802
Received Received - Intake

Cleartext Storage of Sensitive Data in Devolutions PowerShell Universal

Vulnerability report for CVE-2026-16802, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: Devolutions Inc.

Description

Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
devolutions powershell_universal 2026.2.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-312 The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the cleartext storage of sensitive information in the variables feature of Devolutions PowerShell Universal versions 2026.2.2 and earlier. When no vault is selected, secret variables are stored unencrypted on disk, allowing a local attacker with file system access to read these secret values directly.

Detection Guidance

Check for files containing secret variables in cleartext within Devolutions PowerShell Universal installation directories. Look for files with sensitive data stored without encryption, especially in variables or configuration files.

Impact Analysis

If you use Devolutions PowerShell Universal 2026.2.2 or earlier without a vault, an attacker with local file system access could steal sensitive secrets like passwords or API keys stored as variables. This could lead to unauthorized access to systems, data breaches, or further exploitation of your environment.

Compliance Impact

This vulnerability likely violates compliance requirements for GDPR and HIPAA, which mandate protection of sensitive data. Storing secrets in cleartext fails to meet encryption and access control standards, potentially resulting in regulatory penalties, loss of certification, or legal consequences.

Mitigation Strategies

Upgrade to a version of Devolutions PowerShell Universal that addresses this issue. If upgrading is not possible, ensure all sensitive variables are stored in a secure vault and remove any cleartext storage of secrets.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16802. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart