What is CVE-2026-16800?
A 'Code Injection' vulnerability exists in the schedule feature of Devolutions PowerShell Universal 2026.2.2 and earlier. An authenticated user with schedule creation permission can execute arbitrary PowerShell code by injecting crafted schedule parameter names that are concatenated into a script. Updating to the latest version is recommended.
Azərbaycanca: Devolutions PowerShell Universal 2026.2.2 və daha əvvəlki versiyalarda 'Code Injection' zəifliyi aşkarlanıb. Autentifikasiya olunmuş və cədvəl yaratma icazəsi olan istifadəçi, xüsusi hazırlanmış cədvəl parametr adları vasitəsilə skriptə müdaxilə edərək ixtiyari PowerShell kodu icra edə bilər. Məhsulu ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: Devolutions
FAQ2
What permissions are required to exploit CVE-2026-16800 in Devolutions PowerShell Universal?
The attacker must be an authenticated user with schedule creation permission.
How is CVE-2026-16800 exploited?
It is exploited by injecting crafted schedule parameter names that are concatenated into a script, allowing arbitrary PowerShell code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.