CVE-2026-16802
published 2026-07-24CVE-2026-16802: Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file…
PriorityP428medium6.5CVSS 3.1
AVLACLPRLUINSCCHINAN
EPSS
0.08%
0.1th percentile
Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| devolutions | powershell_universal | < 2026.2.3 | 2026.2.3 |
| devolutions | powershell_universal | < 2026.2.3.0 | 2026.2.3.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secr
ghsa_unreviewed·2026-07-24
CVE-2026-16802 [MEDIUM] CWE-312 Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secr
Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected.
VulDB
Devolutions PowerShell Universal up to 2026.2.2 Variables Feature cleartext storage
vuldb·2026-07-24·CVSS 6.5
CVE-2026-16802 [MEDIUM] Devolutions PowerShell Universal up to 2026.2.2 Variables Feature cleartext storage
A vulnerability was found in Devolutions PowerShell Universal up to 2026.2.2. It has been classified as problematic. Affected by this issue is some unknown functionality of the component Variables Feature. This manipulation causes cleartext storage of sensitive information.
This vulnerability appears as CVE-2026-16802. The attack requires local access. There is no available exploit.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-24
Published