Impact
Cleartext storage of sensitive information in the variables feature of Devolutions PowerShell Universal permits a local actor with file‑system access to read secret values that are written to disk when no vault is selected. This constitutes an information disclosure vulnerability that could allow an attacker to obtain credentials or other confidential data, potentially leading to further compromise or privilege escalation. The weakness is classified as CWE‑312, cleartext storage of sensitive information.
Affected Systems
Devolutions PowerShell Universal versions 2026.2.2 and earlier are affected.
Risk and Exploitability
The CVSS score of 6.5 denotes moderate severity while the EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low exploitation probability. Because the attacker must have local file‑system access, the attack vector is local; remote exploitation is not supported by the description.
OpenCVE Enrichment