PatchSiren cyber security CVE debrief
CVE-2026-16800 Devolutions CVE debrief
CVE-2026-16800 is a high-severity vulnerability in Devolutions PowerShell Universal, allowing authenticated users with schedule creation permissions to inject arbitrary PowerShell code. This issue affects versions 2026.2.2 and earlier. The vulnerability exists in the schedule feature, where an authenticated user can execute arbitrary PowerShell code by crafting schedule parameter names that are concatenated into a script invocation. Users of Devolutions PowerShell Universal should apply patches to prevent code injection attacks and review system configurations for potential exposure.
- Vendor
- Devolutions
- Product
- PowerShell Universal
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-24
- Original CVE updated
- 2026-07-29
- Advisory published
- 2026-07-24
- Advisory updated
- 2026-07-29
Who should care
Users of Devolutions PowerShell Universal 2026.2.2 and prior should apply patches to prevent code injection attacks. System administrators, security teams, and operators responsible for managing Devolutions PowerShell Universal deployments should review system configurations, verify patch compliance, and monitor for suspicious activity. Additionally, security teams should review compensating controls for exposed systems while remediation is scheduled and verified.
Technical summary
The vulnerability exists in the schedule feature of Devolutions PowerShell Universal. An authenticated user with schedule creation permission can execute arbitrary PowerShell code by crafting schedule parameter names that are concatenated into a script invocation. This issue affects versions 2026.2.2 and earlier. The vulnerability has a high CVSS score of 8.8, indicating a high severity. Defenders should prioritize patching and review system configurations for potential exposure.
Defensive priority
High priority due to high CVSS score of 8.8 and potential for code injection.
Recommended defensive actions
- Apply patches from Devolutions
- Restrict schedule creation permissions
- Monitor for suspicious schedule creations
- Inventory and update affected systems
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
Evidence from NVD and CVE.org indicates a high-severity vulnerability exists in Devolutions PowerShell Universal. Limited details are available on affected scope, including specific versions and configurations, and vendor remediation efforts. Defenders should verify system configurations, review logs for suspicious activity, and monitor for updates from Devolutions. The CVE record was published on 2026-07-24T15:17:12.963Z and has not been modified since then.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-16800 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-16800
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-16800 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16800
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://devolutions.net/security/advisories/DEVO-2026-0025/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.