CVE-2026-92237
Received Received - Intake

Insertion of Sensitive Information into Log File in Devolutions PowerShell Universal

Vulnerability report for CVE-2026-92237, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: Devolutions Inc.

Description

Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protection key material and other stored credentials via SQL parameter values written to the system log on instances backed by Microsoft SQL Server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
devolutions powershell_universal to 2026.2.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves sensitive information being logged in the slow query logging feature of Devolutions PowerShell Universal versions 2026.2.5 and earlier. An authenticated user with log read permissions can access application tokens, data protection keys, and stored credentials through SQL parameter values written to the system log when using Microsoft SQL Server as the backend.

Impact Analysis

An attacker with log read access could extract sensitive credentials and tokens, potentially leading to unauthorized access to systems, data breaches, or further exploitation of the environment. This could compromise the security of the PowerShell Universal instance and associated data.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. Organizations may face compliance violations, legal penalties, and reputational damage.

Mitigation Strategies

Upgrade Devolutions PowerShell Universal to a version later than 2026.2.5 to address the vulnerability. Disable slow query logging if not required or restrict log read permissions to authorized users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92237. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart