What is CVE-2026-16798?
This vulnerability exists in the automation jobs API of Devolutions PowerShell Universal, where sensitive information is improperly inserted into sent data. An authenticated user with scoped job or script read permissions can obtain another user's stored OAuth refresh token via job read responses that fail to strip this confidential data. Organizations using version 2026.2.2 and earlier should apply the security update immediately.
Azərbaycanca: Bu zəiflik Devolutions PowerShell Universal platformasının avtomatlaşdırma işləri API-sində aşkarlanıb. Müəyyən icazələrə malik autentifikasiya olunmuş istifadəçi, API cavablarında düzgün filtrasiya edilməyən həssas məlumatlar səbəbindən digər istifadəçilərə məxsus OAuth refresh token-lərini əldə edə bilər. 2026.2.2 və daha əvvəlki versiyaları istifadə edən təşkilatlar dərhal təhlükəsizlik yeniləməsini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What permissions does an authenticated user need to exploit CVE-2026-16798?
To exploit the vulnerability, a user must be authenticated to Devolutions PowerShell Universal and possess scoped job or script read permissions.
Which versions of Devolutions PowerShell Universal are affected by CVE-2026-16798?
Version 2026.2.2 and earlier are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.