What is CVE-2026-16802?
A vulnerability in Devolutions PowerShell Universal 2026.2.2 and earlier allows cleartext storage of sensitive data via the variables feature when no vault is selected. This permits a local actor with filesystem access to read secret variable values directly from the disk, exposing sensitive information. Affected users should immediately upgrade to a patched version or configure a vault for secret storage.
Azərbaycanca: Devolutions PowerShell Universal 2026.2.2 və daha əvvəlki versiyalarda 'variables' funksiyasındakı zəiflik, heç bir 'vault' seçilmədikdə məxfi dəyişənlərin diskdə şifrəsiz (cleartext) saxlanmasına səbəb olur. Bu, fayl sisteminə girişi olan lokal aktora 'secret variable' tipli həssas məlumatları birbaşa oxumağa imkan verir. Bu versiyalardan istifadə edən sistemlər dərhal yenilənməli və ya məxfi məlumatların saxlanması üçün mütləq vault konfiqurasiyası tətbiq edilməlidir.
Related CVEs
link basis: shared vendor: Devolutions
FAQ2
Which versions of Devolutions PowerShell Universal are affected by CVE-2026-16802?
Devolutions PowerShell Universal 2026.2.2 and earlier versions are affected by this vulnerability.
What type of data can be exposed by exploiting CVE-2026-16802?
A local actor with filesystem access can read sensitive 'secret variable' data stored in cleartext on the disk via the variables feature.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.