MAIN MENU

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2026-0022

PowerShell Universal is affected by an information disclosure vulnerability.

Affected Products

Devolutions PowerShell Universal 2026.2.0

Change Log

Initial publication - 2026-06-29

Insertion of authentication tokens into AI Agent job API responses

8.5 High - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H

Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in plaintext in job API responses.

CVE(s)

CVE-2026-13437

Remediation and Workarounds

Upgrade to Devolutions PowerShell Universal 2026.2.1 or higher.