Impact
Improper input validation in PowerShell Universal allows an authenticated user with permissions to create or modify apps or endpoints to override existing application or system routes, resulting in unintended request routing and denial of service due to a conflicting URL path. The weakness corresponds to CWE-1289, exposing the application to path manipulation attacks that can disrupt service availability.
Affected Systems
All installations of Devolutions PowerShell Universal prior to version 2026.1.4 are affected. The vendor, Devolutions, has identified this as a flaw in all versions before the 2026.1.4 release.
Risk and Exploitability
The CVSS score is 5.5, indicating a moderate severity. The EPSS score is below 1%, suggesting a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user who already has the authority to create or modify apps or endpoints; the attack vector is therefore limited to authorized users within the target environment.
OpenCVE Enrichment