What is CVE-2026-16801?
A 'Code Injection' vulnerability exists in the variables feature of Devolutions PowerShell Universal 2026.2.2 and earlier. It allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped. Users should update to the latest version immediately.
Azərbaycanca: Devolutions PowerShell Universal 2026.2.2 və daha əvvəlki versiyalarında dəyişənlər funksiyasında 'Code Injection' zəifliyi aşkar edilib. Bu, dəyişən yazma icazəsi olan autentifikasiya edilmiş istifadəçiyə xüsusi hazırlanmış dəyişən dəyəri vasitəsilə ixtiyari PowerShell kodu icra etməyə imkan verir. İstifadəçilərə dərhal ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: Devolutions
FAQ2
Is authentication required to exploit CVE-2026-16801?
Yes, exploiting this vulnerability requires the user to be authenticated and have variable write permission.
Which versions of Devolutions PowerShell Universal are affected by CVE-2026-16801?
Version 2026.2.2 and earlier are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.