Description
Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks.
Published: 2026-07-24
Score: 5.0 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an improper access control flaw that allows any authenticated user possessing only the Reader role to execute automation tests and modify workflow properties. The flaw stems from missing server-side authorization checks, enabling actions that are normally reserved for users with higher privileges. The impact is limited to the ability to alter automation configurations and workflow definitions without proper authorization.

Affected Systems

Devolutions PowerShell Universal version 2026.2.2 and all earlier releases are affected. The issue resides within the automation tests and workflows features of the product.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of extensive automated exploitation. Because the flaw permits a Reader-role user—traditionally a read-only user—to perform privileged actions, the potential impact on configuration integrity and operational stability could be significant. Based on the description, the likely attack vector requires an authenticated user with a Reader role; it is inferred that such a user could trigger the vulnerable actions, but the specific server endpoints or UI paths are not disclosed in the advisory.

Generated by OpenCVE AI on August 12, 2026 at 00:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade to a version that removes the access control flaw for automation tests and workflow properties.
  • If an upgrade is not immediately possible, restrict the Reader role to users who truly need automation test or workflow modification privileges; consider re‑assigning them to a more restrictive role or removing the specific permissions.
  • If the automation tests and workflows are not required for the application, disable these features for the Reader role or disable them entirely to remove the attack surface.

Generated by OpenCVE AI on August 12, 2026 at 00:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Reader Role Access to Automation Tests and Workflow Modification in Devolutions PowerShell Universal

Mon, 03 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Automation Tests and Workflow Features Enabling Reader Role Privilege Escalation

Thu, 30 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Automation Tests and Workflow Features Enabling Reader Role Privilege Escalation

Fri, 24 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions powershell Universal
Vendors & Products Devolutions
Devolutions powershell Universal

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks.
Weaknesses CWE-862
References

Subscriptions

Devolutions Powershell Universal
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-07-24T17:47:16.710Z

Reserved: 2026-07-23T19:24:53.307Z

Link: CVE-2026-16799

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-24T15:17:12.857

Modified: 2026-07-29T20:33:19.830

Link: CVE-2026-16799

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T01:00:04Z

Weaknesses