Description
Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token.
Published:
2026-07-24
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0025/ |
|
History
Fri, 24 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token. | |
| Weaknesses | CWE-201 | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2026-07-24T17:49:40.208Z
Reserved: 2026-07-23T19:24:47.342Z
Link: CVE-2026-16798
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-201
Insertion of Sensitive Information Into Sent Data