Impact
An authenticated user with job or script read permissions can trigger the automation jobs API to return job read responses that include an unstripped OAuth refresh token, allowing the user to access another user's stored token and leading to secret exposure. The vulnerability stems from insufficient sanitization of sensitive data in API responses, classified as CWE‑201 (Information Exposure); the exposed data is a credential that could be used to impersonate the token owner. Affected systems are installations of Devolutions PowerShell Universal version 2026.2.2 and earlier; no later releases are impacted.
Affected Systems
Devolutions PowerShell Universal versions 2026.2.2 and earlier
Risk and Exploitability
The CVSS score of 6.5 indicates moderate impact; the EPSS score of less than 1% suggests a low current likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated account with job or script read permissions, meaning an attack would most likely stem from an insider or a compromised user, and once the flaw is exploited the attacker obtains long‑lived OAuth refresh tokens that can grant persistent unauthorized access.
OpenCVE Enrichment