PatchSiren cyber security CVE debrief
CVE-2026-16800 Devolutions CVE debrief
CVE-2026-16800 is a high-severity vulnerability in Devolutions PowerShell Universal, allowing authenticated users with schedule creation permissions to inject arbitrary PowerShell code. This issue affects versions 2026.2.2 and earlier. The vulnerability exists in the schedule feature, where an authenticated user can execute arbitrary PowerShell code by crafting schedule parameter names that are concatenated into a script invocation. Users of Devolutions PowerShell Universal should apply patches to prevent code injection attacks and review system configurations for potential exposure.
- Vendor
- Devolutions
- Product
- PowerShell Universal
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-24
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-24
- Advisory updated
- 2026-07-27
Who should care
Users of Devolutions PowerShell Universal 2026.2.2 and prior should apply patches to prevent code injection attacks. System administrators, security teams, and operators responsible for managing Devolutions PowerShell Universal deployments should review system configurations, verify patch compliance, and monitor for suspicious activity. Additionally, security teams should review compensating controls for exposed systems while remediation is scheduled and verified.
Technical summary
The vulnerability exists in the schedule feature of Devolutions PowerShell Universal. An authenticated user with schedule creation permission can execute arbitrary PowerShell code by crafting schedule parameter names that are concatenated into a script invocation. This issue affects versions 2026.2.2 and earlier. The vulnerability has a high CVSS score of 8.8, indicating a high severity. Defenders should prioritize patching and review system configurations for potential exposure.
Defensive priority
High priority due to high CVSS score of 8.8 and potential for code injection.
Recommended defensive actions
- Apply patches from Devolutions
- Restrict schedule creation permissions
- Monitor for suspicious schedule creations
- Inventory and update affected systems
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
Evidence from NVD and CVE.org indicates a high-severity vulnerability exists in Devolutions PowerShell Universal. Limited details are available on affected scope, including specific versions and configurations, and vendor remediation efforts. Defenders should verify system configurations, review logs for suspicious activity, and monitor for updates from Devolutions. The CVE record was published on 2026-07-24T15:17:12.963Z and has not been modified since then.
Official resources
-
CVE-2026-16800 CVE record
CVE.org
-
CVE-2026-16800 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-24T15:17:12.963Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.