← Volver al buscador de CVEs

CVE-2026-16798

Devolutions PowerShell Universal

Descripción

Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user-s stored OAuth refresh token via job read responses that fail to strip the refresh token.

CVSS 6.5EPSS 0.22399999999999998%Riesgo 0.66
Ver fuente
Publicación
2026-07-24 15:17:12
Versiones afectadas
<=2026.2.2
Tipo
Software crítico
Última modificación
2026-07-29 20:32:34
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N