Security & compliance
Upholding the highest standards to protect your data and ensure trust.
DEVO-2026-0022
PowerShell Universal is affected by an information disclosure vulnerability.
Affected Products
Devolutions PowerShell Universal 2026.2.0
Change Log
Initial publication - 2026-06-29
Insertion of authentication tokens into AI Agent job API responses
8.5 High - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in plaintext in job API responses.
CVE(s)
CVE-2026-13437
Remediation and Workarounds
Upgrade to Devolutions PowerShell Universal 2026.2.1 or higher.