Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-16798

Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/07/2026
Última modificación:
29/07/2026

Descripción

*** Pendiente de traducción *** Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:devolutions:powershell_universal:*:*:*:*:*:*:*:* 2026.2.3.0 (excluyendo)


Referencias a soluciones, herramientas e información