Impact
Improper control of code generation (Code Injection) in the settings feature of Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to inject and execute arbitrary PowerShell code. The vulnerability arises because crafted setting values are not properly escaped when written to the settings configuration file, resulting in the execution of the injected code with the service's privileges. This flaw can be leveraged to compromise the entire PowerShell Universal instance, enabling attackers to read, modify, or delete data and extend operations to other connected systems.
Affected Systems
Devolutions PowerShell Universal versions 2026.2.3 and earlier across all supported operating systems are affected. Users running legacy releases should verify whether they remain on a vulnerable version before planning remediation.
Risk and Exploitability
Evident CVSS scores are not publicly available, and EPSS is not provided, but the flaw is listed as not in KEV, indicating no widespread exploitation yet. The attack requires authentication and the ability to manage settings, so remediation efforts should focus on restricting those permissions. Should an attacker obtain that level of access, they can execute arbitrary PowerShell scripts and effectively control the server.
OpenCVE Enrichment