Impact
This vulnerability is an improper access control flaw that allows any authenticated user possessing only the Reader role to execute automation tests and modify workflow properties. The flaw stems from missing server-side authorization checks, enabling actions that are normally reserved for users with higher privileges. The impact is limited to the ability to alter automation configurations and workflow definitions without proper authorization.
Affected Systems
Devolutions PowerShell Universal version 2026.2.2 and all earlier releases are affected. The issue resides within the automation tests and workflows features of the product.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of extensive automated exploitation. Because the flaw permits a Reader-role user—traditionally a read-only user—to perform privileged actions, the potential impact on configuration integrity and operational stability could be significant. Based on the description, the likely attack vector requires an authenticated user with a Reader role; it is inferred that such a user could trigger the vulnerable actions, but the specific server endpoints or UI paths are not disclosed in the advisory.
OpenCVE Enrichment