Description
Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the variables configuration file.
Published: 2026-07-24
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated user with permission to write variables can supply a crafted variable that is not properly escaped, enabling the injection of arbitrary PowerShell code into the configuration file. The flaw falls under Code Injection (CWE‑94) and permits an attacker to execute any PowerShell commands on the host, risking total compromise of confidentiality, integrity, and availability.

Affected Systems

Devolutions PowerShell Universal releases 2026.2.2 and earlier are affected. Users running these versions should verify that they are not exposed to unauthorized modification of variables.

Risk and Exploitability

The EPSS score of less than 1% suggests a very low probability of exploitation at present, and the vulnerability is not included in the CISA KEV catalog. However, the flaw provides a direct path to arbitrary code execution for any authenticated user with write rights to variables, and based on the description, it is inferred that only credentials and write permission are required for exploitation, with no additional network exposure necessary. The CVSS score of 8.8 reflects a high severity.

Generated by OpenCVE AI on August 12, 2026 at 01:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a version newer than 2026.2.2 or apply the vendor’s patch to address the code‑generation flaw.
  • Restrict variable write permissions to trusted accounts or enforce a principle of least privilege for users who can modify variables.
  • Audit the variables configuration file for unexpected PowerShell code and monitor for anomalous script execution to detect potential abuse.

Generated by OpenCVE AI on August 12, 2026 at 01:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Code Injection via Unescaped Variable Values in PowerShell Universal

Tue, 04 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Title Variable-Based PowerShell Injection Enables Remote Code Execution in Devolutions PowerShell Universal

Sun, 02 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Title Variable-Based PowerShell Injection Enables Remote Code Execution in Devolutions PowerShell Universal

Thu, 30 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Improper Variable Escaping Enables Arbitrary PowerShell Execution in Devolutions PowerShell Universal

Sun, 26 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Improper Variable Escaping Enables Arbitrary PowerShell Execution in Devolutions PowerShell Universal

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions powershell Universal
Vendors & Products Devolutions
Devolutions powershell Universal

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the variables configuration file.
Weaknesses CWE-94
References

Subscriptions

Devolutions Powershell Universal
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-07-24T17:40:50.106Z

Reserved: 2026-07-23T19:25:01.955Z

Link: CVE-2026-16801

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-24T15:17:13.077

Modified: 2026-07-29T20:33:59.130

Link: CVE-2026-16801

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T01:30:07Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')