Impact
An authenticated user with permission to write variables can supply a crafted variable that is not properly escaped, enabling the injection of arbitrary PowerShell code into the configuration file. The flaw falls under Code Injection (CWE‑94) and permits an attacker to execute any PowerShell commands on the host, risking total compromise of confidentiality, integrity, and availability.
Affected Systems
Devolutions PowerShell Universal releases 2026.2.2 and earlier are affected. Users running these versions should verify that they are not exposed to unauthorized modification of variables.
Risk and Exploitability
The EPSS score of less than 1% suggests a very low probability of exploitation at present, and the vulnerability is not included in the CISA KEV catalog. However, the flaw provides a direct path to arbitrary code execution for any authenticated user with write rights to variables, and based on the description, it is inferred that only credentials and write permission are required for exploitation, with no additional network exposure necessary. The CVSS score of 8.8 reflects a high severity.
OpenCVE Enrichment