Impact
Devolutions PowerShell Universal includes a slow query logging feature that records SQL parameter values to a system log. In versions 2026.2.5 and earlier, sensitive data such as application tokens, data protection keys, and other credentials are unintentionally logged. This vulnerability allows an attacker who can authenticate to the application and has read permission to the log files to capture stored credentials, compromising confidentiality and potentially enabling further attacks.
Affected Systems
The affected product is Devolutions PowerShell Universal, specifically versions 2026.2.5 and all earlier releases.
Risk and Exploitability
The estimated EPSS score is below 1 %, indicating currently low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The exploitation requires authentication with log read rights; a user who meets these prerequisites could read the log file and extract credential strings. No remote code execution or denial‑of‑service conditions are described. The primary risk is the disclosure of encrypted credentials and keys that could be used to compromise the application or downstream systems.
OpenCVE Enrichment