CVE-2026-16802

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
24/07/2026
Last modified:
29/07/2026

Description

Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:devolutions:powershell_universal:*:*:*:*:*:*:*:* 2026.2.3.0 (excluding)


References to Advisories, Solutions, and Tools