PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16798 Devolutions CVE debrief

CVE-2026-16798 is an Insertion of sensitive information into sent data vulnerability in Devolutions PowerShell Universal 2026.2.2 and earlier. The vulnerability allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token. This type of vulnerability can potentially allow attackers to gain unauthorized access to sensitive information. Users of Devolutions PowerShell Universal 2026.2.2 and earlier should be aware of this vulnerability and take steps to mitigate it by reviewing and updating to the latest version, restricting access to the automation jobs API, and monitoring for suspicious activity.

Vendor
Devolutions
Product
PowerShell Universal
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-24
Original CVE updated
2026-07-29
Advisory published
2026-07-24
Advisory updated
2026-07-29

Who should care

Users of Devolutions PowerShell Universal 2026.2.2 and earlier should be aware of this vulnerability and take steps to mitigate it. This includes reviewing and updating to the latest version, restricting access to the automation jobs API, and monitoring for suspicious activity. Security teams and administrators responsible for managing Devolutions PowerShell Universal deployments should prioritize this vulnerability and take immediate action to protect their systems.

Technical summary

The vulnerability is caused by the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier not properly stripping OAuth refresh tokens from job read responses. This allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token. The affected product is Devolutions PowerShell Universal 2026.2.2 and earlier. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. There are no known exploits or attacks in the wild, but users should take steps to mitigate the vulnerability.

Defensive priority

Medium priority

Recommended defensive actions

  • Review and update Devolutions PowerShell Universal to the latest version
  • Restrict access to the automation jobs API
  • Monitor for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record was published on 2026-07-24T15:17:12.750Z and was last modified on 2026-07-27T20:26:57.327Z. The NVD entry is currently Awaiting Analysis. This information is based on the supplied source corpus and may not reflect the current status of the vulnerability. Users should verify the information with the official CVE record and NVD entry for the most up-to-date details.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-16798 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-16798

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-16798 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16798

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.