PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16798 Devolutions CVE debrief

CVE-2026-16798 is an Insertion of sensitive information into sent data vulnerability in Devolutions PowerShell Universal 2026.2.2 and earlier. The vulnerability allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token. This type of vulnerability can potentially allow attackers to gain unauthorized access to sensitive information. Users of Devolutions PowerShell Universal 2026.2.2 and earlier should be aware of this vulnerability and take steps to mitigate it by reviewing and updating to the latest version, restricting access to the automation jobs API, and monitoring for suspicious activity.

Vendor
Devolutions
Product
PowerShell Universal
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-24
Original CVE updated
2026-07-27
Advisory published
2026-07-24
Advisory updated
2026-07-27

Who should care

Users of Devolutions PowerShell Universal 2026.2.2 and earlier should be aware of this vulnerability and take steps to mitigate it. This includes reviewing and updating to the latest version, restricting access to the automation jobs API, and monitoring for suspicious activity. Security teams and administrators responsible for managing Devolutions PowerShell Universal deployments should prioritize this vulnerability and take immediate action to protect their systems.

Technical summary

The vulnerability is caused by the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier not properly stripping OAuth refresh tokens from job read responses. This allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token. The affected product is Devolutions PowerShell Universal 2026.2.2 and earlier. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. There are no known exploits or attacks in the wild, but users should take steps to mitigate the vulnerability.

Defensive priority

Medium priority

Recommended defensive actions

  • Review and update Devolutions PowerShell Universal to the latest version
  • Restrict access to the automation jobs API
  • Monitor for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record was published on 2026-07-24T15:17:12.750Z and was last modified on 2026-07-27T20:26:57.327Z. The NVD entry is currently Awaiting Analysis. This information is based on the supplied source corpus and may not reflect the current status of the vulnerability. Users should verify the information with the official CVE record and NVD entry for the most up-to-date details.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-24T15:17:12.750Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.