What is CVE-2026-16799?
Improper access control in Devolutions PowerShell Universal versions 2026.2.2 and earlier allows an authenticated user with Reader role to execute automation tests and modify workflow properties due to missing server-side authorization checks. Affected users should apply the security patch immediately.
Azərbaycanca: Devolutions PowerShell Universal platformasının 2026.2.2 və əvvəlki versiyalarında avtomatlaşdırma testləri və iş axınları funksiyalarında aşkar edilmiş bu boşluq, yalnız Reader roluna malik autentifikasiya olunmuş istifadəçiyə server tərəfində yetkiləndirmə yoxlamalarının olmaması səbəbindən iş axını xassələrini dəyişməyə və testləri icra etməyə imkan verir. Təsirə məruz qalan istifadəçilər dərhal təhlükəsizlik yamasını tətbiq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
Which platform does CVE-2026-16799 affect, and with what role can it be exploited?
This vulnerability affects Devolutions PowerShell Universal versions 2026.2.2 and earlier. It allows an authenticated user with Reader role to modify workflow properties and execute tests due to missing server-side authorization checks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.