Description
Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protection key material and other stored credentials via SQL parameter values written to the system log on instances backed by Microsoft SQL Server.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

Devolutions PowerShell Universal includes a slow query logging feature that records SQL parameter values to a system log. In versions 2026.2.5 and earlier, sensitive data such as application tokens, data protection keys, and other credentials are unintentionally logged. This vulnerability allows an attacker who can authenticate to the application and has read permission to the log files to capture stored credentials, compromising confidentiality and potentially enabling further attacks.

Affected Systems

The affected product is Devolutions PowerShell Universal, specifically versions 2026.2.5 and all earlier releases.

Risk and Exploitability

The estimated EPSS score is below 1 %, indicating currently low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The exploitation requires authentication with log read rights; a user who meets these prerequisites could read the log file and extract credential strings. No remote code execution or denial‑of‑service conditions are described. The primary risk is the disclosure of encrypted credentials and keys that could be used to compromise the application or downstream systems.

Generated by OpenCVE AI on September 18, 2026 at 14:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Devolutions PowerShell Universal to a version newer than 2026.2.5, which removes the slow query logging flaw.
  • Disable the slow query logging feature to prevent sensitive SQL parameter values from being written to the system log.
  • Restrict read access to the application log files so that only privileged administrators can view them.
  • Implement monitoring of log files for unexpected inclusion of sensitive information and alert administrators.

Generated by OpenCVE AI on September 18, 2026 at 14:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Title Sensitive Information Exposure via Slow Query Logging with SQL Server

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Sensitive Information Exposure via Slow Query Logging with SQL Server

Wed, 16 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions powershell Universal
Vendors & Products Devolutions
Devolutions powershell Universal

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protection key material and other stored credentials via SQL parameter values written to the system log on instances backed by Microsoft SQL Server.
Weaknesses CWE-532
References

Subscriptions

Devolutions Powershell Universal
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-09-16T17:50:21.780Z

Reserved: 2026-09-15T19:37:45.885Z

Link: CVE-2026-92237

cve-icon Vulnrichment

Updated: 2026-09-16T17:50:11.234Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T21:16:49.537

Modified: 2026-09-16T20:38:33.883

Link: CVE-2026-92237

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:30:09Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File