PatchSiren cyber security CVE debrief
CVE-2026-16802 Devolutions CVE debrief
A local actor with file system access can read secret values via secret variables stored in cleartext on disk when no vault is selected in Devolutions PowerShell Universal 2026.2.2 and earlier. This vulnerability affects users of Devolutions PowerShell Universal 2026.2.2 and earlier who store sensitive information in secret variables. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. The CVE record was published on 2026-07-24T15:17:13.180Z and has not been modified since then.
- Vendor
- Devolutions
- Product
- PowerShell Universal
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-24
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-24
- Advisory updated
- 2026-07-27
Who should care
Users of Devolutions PowerShell Universal 2026.2.2 and earlier who store sensitive information in secret variables should verify their systems and consider upgrading to a version that stores sensitive information securely. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess the impact of this vulnerability on their systems and take necessary actions.
Technical summary
The variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier stores sensitive information in cleartext on disk when no vault is selected. This allows a local actor with file system access to read secret values via secret variables. The affected product is Devolutions PowerShell Universal 2026.2.2 and earlier. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. A local actor with file system access can read secret values via secret variables stored in cleartext on disk when no vault is selected. This vulnerability affects users of Devolutions PowerShell Universal 2026.2.2 and earlier who store sensitive information in secret variables, including operators, platform administrators, vulnerability management teams, and security teams who need to assess the impact of this vulnerability on their systems and take necessary actions.
Defensive priority
Medium priority due to the local access requirement and the potential for sensitive information disclosure.
Recommended defensive actions
- Verify that Devolutions PowerShell Universal is properly configured to use a vault for storing sensitive information.
- Restrict file system access to sensitive areas to authorized personnel only.
- Monitor for and apply vendor remediation when available.
- Consider compensating controls such as encryption and access controls.
- Perform regular inventory checks to ensure all systems are accounted for.
- Review relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record was published on 2026-07-24T15:17:13.180Z and was last modified on 2026-07-27T20:26:57.327Z. The NVD entry is currently Awaiting Analysis. This information is based on the CVE record and NVD entry. To verify the affected scope and severity, defenders should review the official CVE record and NVD entry. The CVE record and NVD entry provide the most up-to-date information on this vulnerability. Additionally, defenders should check for any vendor advisories or guidance on mitigating this vulnerability.
Official resources
-
CVE-2026-16802 CVE record
CVE.org
-
CVE-2026-16802 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-24T15:17:13.180Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.